Vulnerabilità · 34 giorni fa
SharePoint passa da bypass a RCE senza credenziali VulnCheck ha pubblicato un exploit funzionante per Microsoft SharePoint dopo 13 giorni di divulgazioni: la catena unisce CVE-2026-55040 e CVE-2026-63520 e porta a RCE senza credenziali. CVE-2026-55040 è già in KEV e lo sfruttamento in rete era già stato riportato.
Il primo bug consente di forgiare un JWT e farsi accettare come utente privilegiato. Il secondo sfrutta una creazione insicura di oggetti .NET dentro SharePoint. Insieme, un controllo di accesso saltato diventa esecuzione di codice sul server, quindi compromissione completa di un'istanza esposta.
Per chi gestisce SharePoint Internet-facing, il punto non è più la gravità separata delle due falle ma la loro composizione. Una patch parziale non basta a cambiare il quadro se la catena resta sfruttabile come varco remoto verso il server e i dati che raggiunge.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Patch Microsoft: 5002891.
Patch disponibile KB5002891 Scarica →
Data di correzione federale CISA 21 ago · data superata
CVE-2026-63520 NVD KEV
CVSS 8.1 HIGH: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Patch Microsoft: 5002905.
Patch disponibile KB5002905 Scarica →
Cronologia Fonti 17 fonti che coprono questa storia
Cybersecurity Dive 25 ago
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
Rapid7 24 ago
Ra Microsoft Sharepoint Remote Code Execution CVE-2026-63520
A technical analysis of CVE-2026-63520, a remote code execution vulnerability due to an unrestricted .NET type instantiation, affecting Microsoft SharePoint.
VulnCheck 24 ago
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog | VulnCheck
Building a complete SharePoint exploit chain to get unauthenticated RCE via unsafe .NET type instantiation.
BleepingComputer 17 ago
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new
CSO Online 13 ago
Researcher creates workaround for Microsoft Defender security patch
The PoC posted by Nightmare Eclipse, who has been feuding with Microsoft for months, grants an attacker system-level privileges once they gain any access.
The Hacker News 12 ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
TechCrunch Security 12 ago
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
SecurityWeek 12 ago
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Infosecurity Magazine 12 ago
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Help Net Security 12 ago
Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security
North Korea's Lazarus group used fake job offers and a Windows zero-day to target defense and aerospace organizations.
INCIBE-CERT 12 ago
Boletín de seguridad de Microsoft: agosto de 2026
La publicación de actualizaciones de seguridad de Microsoft, correspondiente a la publicación de vulne
Help Net Security 12 ago
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) - Help Net Security
Microsoft's August 2026 Patch Tuesday delivered 400+ security fixes, including one for an actively exploited zero-day flaw (CVE-2026-68820).
Entità CVE-2026-55040 CVE-2026-63520 Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-08-11
Editions Storie correlate
Vulnerabilità · 34 giorni fa
SharePoint passa da bypass a RCE senza credenziali VulnCheck ha pubblicato un exploit funzionante per Microsoft SharePoint dopo 13 giorni di divulgazioni: la catena unisce CVE-2026-55040 e CVE-2026-63520 e porta a RCE senza credenziali. CVE-2026-55040 è già in KEV e lo sfruttamento in rete era già stato riportato.
Il primo bug consente di forgiare un JWT e farsi accettare come utente privilegiato. Il secondo sfrutta una creazione insicura di oggetti .NET dentro SharePoint. Insieme, un controllo di accesso saltato diventa esecuzione di codice sul server, quindi compromissione completa di un'istanza esposta.
Per chi gestisce SharePoint Internet-facing, il punto non è più la gravità separata delle due falle ma la loro composizione. Una patch parziale non basta a cambiare il quadro se la catena resta sfruttabile come varco remoto verso il server e i dati che raggiunge.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Patch Microsoft: 5002891.
Patch disponibile KB5002891 Scarica →
Data di correzione federale CISA 21 ago · data superata
CVE-2026-63520 NVD KEV
CVSS 8.1 HIGH: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Patch Microsoft: 5002905.
Patch disponibile KB5002905 Scarica →
Cronologia Fonti 17 fonti che coprono questa storia
Cybersecurity Dive 25 ago
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
Rapid7 24 ago
Ra Microsoft Sharepoint Remote Code Execution CVE-2026-63520
A technical analysis of CVE-2026-63520, a remote code execution vulnerability due to an unrestricted .NET type instantiation, affecting Microsoft SharePoint.
VulnCheck 24 ago
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog | VulnCheck
Building a complete SharePoint exploit chain to get unauthenticated RCE via unsafe .NET type instantiation.
BleepingComputer 17 ago
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new
CSO Online 13 ago
Researcher creates workaround for Microsoft Defender security patch
The PoC posted by Nightmare Eclipse, who has been feuding with Microsoft for months, grants an attacker system-level privileges once they gain any access.
The Hacker News 12 ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
TechCrunch Security 12 ago
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
SecurityWeek 12 ago
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Infosecurity Magazine 12 ago
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Help Net Security 12 ago
Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security
North Korea's Lazarus group used fake job offers and a Windows zero-day to target defense and aerospace organizations.
INCIBE-CERT 12 ago
Boletín de seguridad de Microsoft: agosto de 2026
La publicación de actualizaciones de seguridad de Microsoft, correspondiente a la publicación de vulne
Help Net Security 12 ago
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) - Help Net Security
Microsoft's August 2026 Patch Tuesday delivered 400+ security fixes, including one for an actively exploited zero-day flaw (CVE-2026-68820).
Entità CVE-2026-55040 CVE-2026-63520 Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-08-11
Editions Storie correlate