// Alert

Microsoft 365 threat report

Researchers disclosed an authentication bypass and remote code execution vulnerability chain affecting Microsoft SharePoint Server on-premises. CVE-2026-55040 allows unauthenticated attackers to impersonate arbitrary users via JWT validation bypasses, which can be chained with CVE-2026-63520 (unsafe .NET type instantiation) to achieve code execution as the Windows service account. The vulnerabilities affect SharePoint Server Subscription Edition, 2019, and 2016; exploitation requires knowledge of the target user's Active Directory SID or UPN. Microsoft shipped a July patch addressing CVE-2026-55040; August patches for CVE-2026-63520 were not yet publicly available at time of publication.

// Get alerts for Microsoft 365