// Microsoft 365HIGH
Researchers disclosed an authentication bypass and remote code execution vulnerability chain affecting Microsoft SharePoint Server on-premises. CVE-2026-55040 allows unauthenticated attackers to impersonate arbitrary users via JWT validation bypasses, which can be chained with CVE-2026-63520 (unsafe .NET type instantiation) to achieve code execution as the Windows service account. The vulnerabilities affect SharePoint Server Subscription Edition, 2019, and 2016; exploitation requires knowledge of the target user's Active Directory SID or UPN. Microsoft shipped a July patch addressing CVE-2026-55040; August patches for CVE-2026-63520 were not yet publicly available at time of publication.
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reachi(opens in a new tab)
- Hackers leverage new Microsoft SharePoint exploit in attacks(opens in a new tab)
- Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Exe(opens in a new tab)
- SharePoint CVE-2026-55040 Comes Under Attack Following Public Ex(opens in a new tab)
- Attackers Exploit SharePoint Authentication Bypass After Public (opens in a new tab)
- Hackers Actively Exploiting Microsoft SharePoint Vulnerability F(opens in a new tab)
// Get alerts for Microsoft 365