Microsoft's SharePoint bug had a missing half. Someone just published it — and honeypots are already lighting up

The JWT auth bypass we told you about two weeks ago just got its second half: a working RCE chain, two public PoCs, and active probing as of this…

Aliteq
Priya Nair · Software & Systems Editor

What's actually happening

CVE-2026-55040 (patched, PoC public since Aug 11) bypasses JWT token validation to impersonate any SharePoint user or admin without credentials.

What's actually happening

CVE-2026-63520 (PoC public since Aug 24) lets an authenticated-as-admin attacker instantiate unsafe .NET types through SharePoint's Business Connectivity Services and achieve full RCE.

What's actually happening

Chained together, the two flaws take an attacker from zero access to code execution on an unpatched, internet-facing SharePoint server.

What's actually happening

The August 2026 cumulative update (KB5002893) closes the RCE half by restricting BCS to an explicit allow-list of safe .NET types.

What's actually happening

Honeypots are seeing the JWT bypass exercised and admin functions probed as of August 25 — Defused reports no confirmed code execution in the wild yet, but the reconnaissance stage is already live.

Two weeks from PoC to chain is fast, even by 2026 standards

My honest take: what's notable isn't the bug itself, it's the timeline. Thirteen days separate the first public PoC and the second one that completes the chain into RCE. That's not a coincidence —…

Aliteq

Read the full story

Microsoft's SharePoint bug had a missing half. Someone just published it — and honeypots are already lighting up

Read the full story on Aliteq