VulnCheck released a working exploit for Microsoft SharePoint on day 13 of disclosure, chaining CVE-2026-55040 and CVE-2026-63520 to reach unauthenticated remote code execution. CVE-2026-55040 is already in CISA’s Known Exploited Vulnerabilities catalog, and exploitation has been reported.
The chain starts with a JWT token authentication bypass that lets an attacker pose as a privileged user. That access then feeds SharePoint unsafe .NET type instantiation through Business Connectivity Services, so the server builds attacker-influenced objects and ends up executing code instead of just accepting the forged login.
For operators, the important shift is that these are no longer separate issues to judge in isolation. If SharePoint is internet-facing, a bypass that once looked like partial impact can now become full remote compromise, with whatever data and downstream systems that server can reach.
story_meaning":"A SharePoint auth bypass plus unsafe .NET instantiation now forms a public unauthenticated RCE chain." ,
why_now":"Public exploit chain is out; one CVE is already in KEV"}]}}}】disabled to=final રૂપે incorrect JSON. Need valid JSON only. Let's fix. The story_meaning and why_now fields should be strings or null. Let's produce proper object. Also meta_title <=60 chars.
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Microsoft patch: 5002891.
CVSS 8.1 HIGH: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Microsoft patch: 5002905.
Ra Microsoft Sharepoint Remote Code Execution CVE-2026-63520
A technical analysis of CVE-2026-63520, a remote code execution vulnerability due to an unrestricted .NET type instantiation, affecting Microsoft SharePoint.