Attackers exploiting RCE Chain with PoC to target SharePoint
27 Aug 2026
Security researchers from Defused, a threat intelligence company, have discovered two vulnerabilities in Microsoft SharePoint that attackers are exploiting to execute arbitrary code on unpatched servers.
Through this blog, we will understand what the vulnerabilities in Microsoft SharePoint are about, the threats they pose, and how organizations can defend against the threats posed by them.
About the vulnerabilities
|
Vendor + component affected |
CVEs/CVSS Score/Type |
Versions affected |
About
|
|
Microsoft + SharePoint Server 2016, 2019, and Subscription Edition
|
CVE-2026-55040/9.1(Critical)/ Authentication Bypass
CVE-2026-63520/8.1(High)/ Remote Code Execution
|
|
CVE-2026-55040 –
This flaw lets unauthorized attackers carry out impersonation attacks by getting past authentication features over a network.
CVE-2026-63520 – An unauthenticated attacker can exploit this flaw to execute arbitrary code remotely on a SharePoint Server. |
The threat posed by the vulnerabilities
|
Vulnerability |
What can an attacker do? |
|
CVE-2026-55040 |
|
|
CVE-2026-63520 |
|
Microsoft has already released updates addressing the vulnerabilities. Organizations should immediately apply the latest applicable Security updates.
SharkStriker’s recommendation
- Immediately patch affected SharePoint servers.
- Prioritize Internet-facing SharePoint systems.
- Verify SharePoint versions after patching.
- Restrict unnecessary Internet exposure.
SharkStriker’s actions
- Shared the advisory with the concerned team.
- Recommended immediate patching and prioritization of Internet-facing systems.
- Advised monitoring for exploitation attempts.