Microsoft: Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Microsoft: Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Critical SharePoint Vulnerabilities Enable Unauthenticated Remote Takeover

Two severe Microsoft SharePoint Server vulnerabilities CVE-2026-55040 (CVSS 9.1) and CVE-2026-63520 (CVSS 8.1) can be chained to allow unauthenticated remote attackers to gain full control of unpatched servers.

The first flaw, CVE-2026-55040, is an authentication bypass in SharePoint’s JSON Web Token (JWT) handler. Researchers at Rapid7 discovered that disabled security checks including the RequireSignedTokens setting allowed attackers to forge unsigned JWTs and impersonate users, including administrators, by knowing only a target’s security identifier or principal name (e.g., user@domain). The vulnerability was disclosed on July 14, 2026, with details published on August 11.

The second flaw, CVE-2026-63520, is a remote code execution (RCE) vulnerability in SharePoint’s Business Connectivity Services (BCS), which connects external data systems to SharePoint. VulnCheck researchers found that BCS improperly restricted .NET types in Business Data Connectivity models, enabling attackers to exploit the System.Web.UI.LosFormatter class for deserialization attacks. A successful exploit grants arbitrary code execution on the server.

Attack Chain: Threat actors first exploit CVE-2026-55040 to bypass authentication, then use the forged credentials to upload a malicious BDC model via CVE-2026-63520, triggering RCE. VulnCheck released exploit details and detection guidance on August 24, 2026.

Scope & Impact: Approximately 21,000 on-premises SharePoint instances were identified as potentially vulnerable, per Censys data. SharePoint Online (Microsoft 365) is unaffected. CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on August 18, confirming active exploitation.

Microsoft released patches in August 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Unpatched, internet-facing servers are at high risk.

Source: https://cybersecuritynews.com/sharepoint-flaws-chained-to-hack-servers/

Microsoft Security Response Center cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security-response-center

"id": "MIC1787733576",
"linkid": "microsoft-security-response-center",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Approximately 21,000 '
                                              'on-premises SharePoint '
                                              'instances',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Microsoft SharePoint Server Users',
                        'type': 'Software/Service'}],
 'attack_vector': 'Remote',
 'date_detected': '2026-07-14',
 'date_publicly_disclosed': '2026-08-11',
 'date_resolved': '2026-08',
 'description': 'Two severe Microsoft SharePoint Server vulnerabilities '
                '(CVE-2026-55040 and CVE-2026-63520) can be chained to allow '
                'unauthenticated remote attackers to gain full control of '
                'unpatched servers. The first flaw, CVE-2026-55040, is an '
                'authentication bypass in SharePoint’s JSON Web Token (JWT) '
                'handler. The second flaw, CVE-2026-63520, is a remote code '
                'execution (RCE) vulnerability in SharePoint’s Business '
                'Connectivity Services (BCS). Attackers exploit CVE-2026-55040 '
                'to bypass authentication and then use the forged credentials '
                'to upload a malicious BDC model via CVE-2026-63520, '
                'triggering RCE.',
 'impact': {'operational_impact': 'Full control of unpatched servers',
            'systems_affected': 'SharePoint Server Subscription Edition, '
                                'SharePoint Server 2019, SharePoint Enterprise '
                                'Server 2016'},
 'post_incident_analysis': {'corrective_actions': 'Apply Microsoft patches and '
                                                  'enforce security best '
                                                  'practices for SharePoint '
                                                  'deployments',
                            'root_causes': 'Disabled security checks in '
                                           'SharePoint’s JWT handler and '
                                           'improper restriction of .NET types '
                                           'in Business Data Connectivity '
                                           'models'},
 'recommendations': 'Patch vulnerable SharePoint servers immediately and '
                    'ensure internet-facing servers are updated.',
 'references': [{'source': 'Rapid7'},
                {'date_accessed': '2026-08-24', 'source': 'VulnCheck'},
                {'source': 'Censys'},
                {'date_accessed': '2026-08-18', 'source': 'CISA'}],
 'regulatory_compliance': {'regulatory_notifications': 'CISA added '
                                                       'CVE-2026-55040 to its '
                                                       'Known Exploited '
                                                       'Vulnerabilities '
                                                       'catalog on August 18, '
                                                       '2026'},
 'response': {'containment_measures': 'Patching vulnerable systems',
              'remediation_measures': 'Microsoft released patches in August '
                                      '2026'},
 'title': 'Critical SharePoint Vulnerabilities Enable Unauthenticated Remote '
          'Takeover',
 'type': ['Authentication Bypass', 'Remote Code Execution'],
 'vulnerability_exploited': ['CVE-2026-55040', 'CVE-2026-63520']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.