// Microsoft 365HIGH
Public exploit code was released for two SharePoint vulnerabilities (CVE-2026-55040 authentication bypass and CVE-2026-63520 RCE) that can be chained for unauthenticated remote code execution. Threat actors have begun probing SharePoint environments following disclosure. Over 8,700 internet-facing SharePoint instances are potentially vulnerable.
- SharePoint Exploit Code Puts Internet-Facing Servers At Risk(opens in a new tab)
- CISA flags four actively exploited flaws in Windows, SharePoint,(opens in a new tab)
// Get alerts for Microsoft 365