An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server,according to a Monday blog postby researchers at VulnCheck.
The sequence involves a critical authentication bypass vulnerability, tracked asCVE-2026-55040, and an improper input validation flaw, tracked asCVE-2026-63520. A proof of concept was previously disclosed Aug. 11 by researchers at cybersecurity firm Rapid7.
Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful, To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520.
“The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,”Vulncheck researchers said in their post.
Exploitation was confirmed against the first part of the attack sequence within days of Rapid7’s initial analysis. VulnCheck added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on Aug. 12, and theCybersecurity and Infrastructure Security Agencyadded the flaw to its catalog on Aug. 18.
VulnCheck researchers found about 8,500 SharePoint servers were visible online.
Researchers from Defused said Tuesday they can already see probing activity against its honeypots involving the chained sequence,according to a post on X.
CISApreviously warned in Julythat multiple vulnerabilities in SharePoint were facing exploitation.
Filed Under:Vulnerability,Threats
