// Alert

Microsoft 365 threat report

Public exploit code was released for two SharePoint vulnerabilities (CVE-2026-55040 authentication bypass and CVE-2026-63520 RCE) that can be chained for unauthenticated remote code execution. Threat actors have begun probing SharePoint environments following disclosure. Over 8,700 internet-facing SharePoint instances are potentially vulnerable.

// Get alerts for Microsoft 365