Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, campaign, rce, exploit-tooling] ยท confidence: high ยท affected_sectors: [technology, government, education] ยท au_impact: true

Attackers Chain Microsoft SharePoint RCE Flaws (CVE-2026-55040 + CVE-2026-63520)

Threat-intelligence firm Defused reported attackers chaining the SharePoint JWT authentication-bypass flaw CVE-2026-55040 with the Business Connectivity Services RCE CVE-2026-63520 in attacks against its honeypots. Both have public proof-of-concept exploits (Rapid7 on 11 August; VulnCheck on 24 August), and the first PoC was weaponised within a day. Shadowserver tracks more than 8,700 internet-exposed SharePoint servers.

Attribute Detail
Date 2026-08-26
Vector SharePoint JWT bypass + BCS RCE chain
Exposure ~8,700+ internet-exposed SharePoint servers
Mitigation Apply Microsoft patch; restrict SharePoint exposure
Source BleepingComputer โ€” Tier 2/4 High

Ready-to-use chained RCE on a widely deployed on-premises platform makes this a broad patching priority for Australian and New Zealand government, education and enterprise networks.

Source