"We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots," Defused warned — a short, stark line that understates how quickly publicly released exploit code has changed a pair of SharePoint bugs from research curiosities into active targets.
Defused honeypots and observed probes
Threat intelligence firm Defused reported on August 25 that attackers are chaining two Microsoft SharePoint vulnerabilities in live probes against its honeypots. Defused said the campaign begins with the JWT bypass (CVE-2026-55040), followed by "heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520." As of that report Defused added, "No code execution observed yet," but the activity shows a clear, automated pattern: authentication bypass, credential- or privilege-harvest, then service-specific probing.
CVE-2026-55040: JWT authentication bypass and rapid weaponization
The first link in the chain is CVE-2026-55040, an authentication bypass flaw in SharePoint's JWT token validation pipeline that allows unauthenticated attackers to perform operations as a SharePoint site user or administrator. Rapid7 security researcher Stephen Fewer published a proof-of-concept (PoC) exploit for CVE-2026-55040 on August 11. Defused reported that one day after that PoC went public, Rapid7's exploit code had already been weaponized in attacks — a rapid transition from disclosure to exploitation that underscores how quickly internet-exposed platforms can be targeted once reliable exploit code is released.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadCVE-2026-63520: Business Connectivity Services RCE PoC and chaining risk
The second vulnerability, CVE-2026-63520, affects SharePoint's Business Connectivity Services (BCS). On August 24 VulnCheck researcher Jonathan Peterson released a public PoC for CVE-2026-63520. According to Defused, attackers are now attempting to chain CVE-2026-55040 and CVE-2026-63520 to achieve remote code execution (RCE) on unpatched SharePoint servers. Microsoft has described CVE-2026-63520 as an "attractive target for threat actors," although the company has not labeled it as exploited in the wild.
CISA and Microsoft's steps, and the broader SharePoint threat picture
The U.S. Cybersecurity and Infrastructure Security Agency ordered federal agencies and network defenders on August 18 to secure SharePoint servers against ongoing CVE-2026-55040 attacks. Earlier, on July 15, CISA warned defenders to secure their servers against active exploitation of three other SharePoint vulnerabilities — CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 — that were being used to compromise internet-exposed on-premises SharePoint Server instances. On Tuesday, CISA also confirmed that CVE-2026-45659, previously flagged as exploited in the wild since early July, is now being exploited in ransomware attacks.
Shadowserver, the internet security non-profit, reports more than 8,700 Microsoft SharePoint servers exposed online. Shadowserver's count does not distinguish how many of those are intentionally deployed honeypots versus production servers that may still be unpatched; Defused itself noted uncertainty about how many exposed instances have been secured against these flaws.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: expect automated probing to continue. Defused's telemetry shows a pattern—JWT bypass exercised, then targeted BCS probing—that defenders should watch for in logs and honeypots, and remediate on exposed SharePoint servers accordingly.
- Policymakers and regulators: CISA has already issued targeted guidance and federal orders; the agency's repeated advisories and the confirmation that at least one SharePoint RCE (CVE-2026-45659) is now tied to ransomware sharpen the case for stricter controls on internet-exposed on-premises services and adherence to vendor hardening guidance.
- Affected enterprises and procurement leaders: the presence of public PoCs — published by Rapid7's Stephen Fewer (Aug 11) and VulnCheck's Jonathan Peterson (Aug 24) — means exploit code is trivially accessible. Shadowserver's count of 8,700+ exposed servers highlights scale; organizations should prioritize patching or hardening SharePoint Server instances and avoid direct internet exposure where possible.
The arc of this episode is familiar and blunt: public PoCs, rapid weaponization, automated probing, and risk of escalation into RCE and ransomware. The Blue Report 2026 — which measures defenses technique by technique across 338 million simulations run in customer production environments — cautions that "overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." Against that backdrop the unresolved figure from Shadowserver — how many of those 8,700+ exposed instances are patched, unreachable, or deliberate traps — stands out as the practical question security teams must answer now.




