Vulnerabilities · 34 days ago
VulnCheck Chains SharePoint Bypass Into RCE VulnCheck released a working exploit for Microsoft SharePoint on day 13 of disclosure, chaining CVE-2026-55040 and CVE-2026-63520 to reach unauthenticated remote code execution. CVE-2026-55040 is already in CISA’s Known Exploited Vulnerabilities catalog, and exploitation has been reported.
The chain starts with a JWT token authentication bypass that lets an attacker pose as a privileged user. That access then feeds SharePoint unsafe .NET type instantiation through Business Connectivity Services, so the server builds attacker-influenced objects and ends up executing code instead of just accepting the forged login.
For operators, the important shift is that these are no longer separate issues to judge in isolation. If SharePoint is internet-facing, a bypass that once looked like partial impact can now become full remote compromise, with whatever data and downstream systems that server can reach.
story_meaning": "A SharePoint auth bypass plus unsafe .NET instantiation now forms a public unauthenticated RCE chain." ,
why_now": "Public exploit chain is out; one CVE is already in KEV"}]}}}】disabled to=final રૂપે incorrect JSON. Need valid JSON only. Let's fix. The story_meaning and why_now fields should be strings or null. Let's produce proper object. Also meta_title <=60 chars.
NVD KEV
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Microsoft patch: 5002891.
Patch available KB5002891 Download →
CISA federal remediation date Aug 21 · date passed
CVE-2026-63520 NVD KEV
CVSS 8.1 HIGH: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Microsoft patch: 5002905.
Patch available KB5002905 Download →
Timeline Sources 17 sources covering this story
Cybersecurity Dive Aug 25
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
Rapid7 Aug 24
Ra Microsoft Sharepoint Remote Code Execution CVE-2026-63520
A technical analysis of CVE-2026-63520, a remote code execution vulnerability due to an unrestricted .NET type instantiation, affecting Microsoft SharePoint.
VulnCheck Aug 24
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog | VulnCheck
Building a complete SharePoint exploit chain to get unauthenticated RCE via unsafe .NET type instantiation.
BleepingComputer Aug 17
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new
CSO Online Aug 13
Researcher creates workaround for Microsoft Defender security patch
The PoC posted by Nightmare Eclipse, who has been feuding with Microsoft for months, grants an attacker system-level privileges once they gain any access.
The Hacker News Aug 12
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
TechCrunch Security Aug 12
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
SecurityWeek Aug 12
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Infosecurity Magazine Aug 12
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Help Net Security Aug 12
Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security
North Korea's Lazarus group used fake job offers and a Windows zero-day to target defense and aerospace organizations.
INCIBE-CERT Aug 12
Boletín de seguridad de Microsoft: agosto de 2026
La publicación de actualizaciones de seguridad de Microsoft, correspondiente a la publicación de vulne
Help Net Security Aug 12
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) - Help Net Security
Microsoft's August 2026 Patch Tuesday delivered 400+ security fixes, including one for an actively exploited zero-day flaw (CVE-2026-68820).
Entities CVE-2026-55040 CVE-2026-63520 Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-08-11
Editions Related stories
Vulnerabilities · 34 days ago
VulnCheck Chains SharePoint Bypass Into RCE VulnCheck released a working exploit for Microsoft SharePoint on day 13 of disclosure, chaining CVE-2026-55040 and CVE-2026-63520 to reach unauthenticated remote code execution. CVE-2026-55040 is already in CISA’s Known Exploited Vulnerabilities catalog, and exploitation has been reported.
The chain starts with a JWT token authentication bypass that lets an attacker pose as a privileged user. That access then feeds SharePoint unsafe .NET type instantiation through Business Connectivity Services, so the server builds attacker-influenced objects and ends up executing code instead of just accepting the forged login.
For operators, the important shift is that these are no longer separate issues to judge in isolation. If SharePoint is internet-facing, a bypass that once looked like partial impact can now become full remote compromise, with whatever data and downstream systems that server can reach.
story_meaning": "A SharePoint auth bypass plus unsafe .NET instantiation now forms a public unauthenticated RCE chain." ,
why_now": "Public exploit chain is out; one CVE is already in KEV"}]}}}】disabled to=final રૂપે incorrect JSON. Need valid JSON only. Let's fix. The story_meaning and why_now fields should be strings or null. Let's produce proper object. Also meta_title <=60 chars.
NVD KEV
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Microsoft patch: 5002891.
Patch available KB5002891 Download →
CISA federal remediation date Aug 21 · date passed
CVE-2026-63520 NVD KEV
CVSS 8.1 HIGH: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Microsoft patch: 5002905.
Patch available KB5002905 Download →
Timeline Sources 17 sources covering this story
Cybersecurity Dive Aug 25
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
Rapid7 Aug 24
Ra Microsoft Sharepoint Remote Code Execution CVE-2026-63520
A technical analysis of CVE-2026-63520, a remote code execution vulnerability due to an unrestricted .NET type instantiation, affecting Microsoft SharePoint.
VulnCheck Aug 24
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog | VulnCheck
Building a complete SharePoint exploit chain to get unauthenticated RCE via unsafe .NET type instantiation.
BleepingComputer Aug 17
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new
CSO Online Aug 13
Researcher creates workaround for Microsoft Defender security patch
The PoC posted by Nightmare Eclipse, who has been feuding with Microsoft for months, grants an attacker system-level privileges once they gain any access.
The Hacker News Aug 12
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
TechCrunch Security Aug 12
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
SecurityWeek Aug 12
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Infosecurity Magazine Aug 12
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Help Net Security Aug 12
Lazarus hackers pair fake job offers with Windows zero-day exploit - Help Net Security
North Korea's Lazarus group used fake job offers and a Windows zero-day to target defense and aerospace organizations.
INCIBE-CERT Aug 12
Boletín de seguridad de Microsoft: agosto de 2026
La publicación de actualizaciones de seguridad de Microsoft, correspondiente a la publicación de vulne
Help Net Security Aug 12
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) - Help Net Security
Microsoft's August 2026 Patch Tuesday delivered 400+ security fixes, including one for an actively exploited zero-day flaw (CVE-2026-68820).
Entities CVE-2026-55040 CVE-2026-63520 Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-08-11
Editions Related stories