type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, campaign, rce, exploit-tooling] ยท confidence: high ยท affected_sectors: [technology, government, education] ยท au_impact: true
Attackers Chain Microsoft SharePoint RCE Flaws (CVE-2026-55040 + CVE-2026-63520)
Threat-intelligence firm Defused reported attackers chaining the SharePoint JWT authentication-bypass flaw CVE-2026-55040 with the Business Connectivity Services RCE CVE-2026-63520 in attacks against its honeypots. Both have public proof-of-concept exploits (Rapid7 on 11 August; VulnCheck on 24 August), and the first PoC was weaponised within a day. Shadowserver tracks more than 8,700 internet-exposed SharePoint servers.
| Attribute | Detail |
|---|---|
| Date | 2026-08-26 |
| Vector | SharePoint JWT bypass + BCS RCE chain |
| Exposure | ~8,700+ internet-exposed SharePoint servers |
| Mitigation | Apply Microsoft patch; restrict SharePoint exposure |
| Source | BleepingComputer โ Tier 2/4 High |
Ready-to-use chained RCE on a widely deployed on-premises platform makes this a broad patching priority for Australian and New Zealand government, education and enterprise networks.