Executive Summary
In August 2026, threat actors began actively exploiting a chained vulnerability in Microsoft SharePoint servers, combining CVE-2026-55040 (JWT authentication bypass) and CVE-2026-63520 (Business Connectivity Services RCE) to achieve remote code execution on unpatched systems. The attack chain allows unauthenticated attackers to first bypass authentication through JWT token validation flaws, then escalate to full code execution via SharePoint's Business Connectivity Services. With over 8,700 SharePoint servers exposed online and proof-of-concept exploits publicly available, CISA ordered federal agencies to immediately patch their systems as exploitation was detected in honeypots within days of PoC release. This incident represents a critical escalation in SharePoint targeting, with CISA having flagged 15 actively exploited SharePoint vulnerabilities since 2021, eight of which were used by ransomware groups. The rapid weaponization timeline demonstrates how quickly adversaries adapt public exploits for mass scanning and targeted attacks against enterprise collaboration platforms.
Why This Matters Now
SharePoint servers remain prime targets for ransomware groups and nation-state actors due to their central role in enterprise data storage and collaboration, making immediate patching and network segmentation critical as exploit chains become increasingly sophisticated.
Attack Path Analysis
Attackers exploited a chained Microsoft SharePoint vulnerability (CVE-2026-55040 + CVE-2026-63520) to bypass JWT authentication and achieve remote code execution on exposed SharePoint servers. The attack progressed from initial authentication bypass through privilege escalation via Business Connectivity Services, enabling lateral movement within the SharePoint environment, establishing command and control channels, and potentially leading to data exfiltration and ransomware deployment as observed in similar SharePoint attack campaigns.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited CVE-2026-55040 JWT token validation bypass flaw to gain unauthorized access to SharePoint servers without valid credentials, targeting over 8,700 internet-exposed SharePoint instances
Related CVEs
CVE-2024-38094
CVSS 7.2Microsoft SharePoint Server authentication bypass vulnerability allowing unauthenticated attackers to bypass authentication checks and perform operations as SharePoint user or administrator.
Affected Products:
Microsoft SharePoint Server – 2016, 2019, Subscription Edition
Exploit Status:
exploited in the wildCVE-2024-38093
CVSS 4.3Microsoft SharePoint Server remote code execution vulnerability in Business Connectivity Services allowing attackers to execute arbitrary code on targeted SharePoint Server.
Affected Products:
Microsoft SharePoint Server – 2016, 2019, Subscription Edition
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Exploit Public-Facing Application
Process Injection
Command and Scripting Interpreter
Exploitation for Privilege Escalation
Account Discovery
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Software Platforms and Applications
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21(2)(a)
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical SharePoint RCE vulnerabilities enable authentication bypass and remote code execution, threatening sensitive government data and operations requiring immediate patching.
Financial Services
SharePoint exploitation chain allows unauthorized access and code execution in financial institutions, risking compliance violations and customer data exposure.
Health Care / Life Sciences
Remote code execution vulnerabilities in SharePoint threaten HIPAA compliance and patient data security, requiring urgent mitigation in healthcare environments.
Higher Education/Acadamia
SharePoint authentication bypass and RCE flaws expose academic institutions to data breaches and ransomware attacks targeting research and student information.
Sources
- Hackers target Microsoft SharePoint RCE chain with PoC exploithttps://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/Verified
- Microsoft Security Response Center - SharePoint Server Vulnerabilitieshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38094Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Rapid7 Research - SharePoint Authentication Bypass Analysishttps://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would have constrained this SharePoint exploitation by limiting attacker reachability and reducing blast radius through workload segmentation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric controls would likely have constrained the scope of initial access by limiting which SharePoint services and resources were reachable from the compromised entry point.
Control: Zero Trust Segmentation
Mitigation: Micro-segmentation policies would likely have limited the scope of privilege escalation by constraining access between SharePoint service components and restricting administrative function reachability.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have constrained lateral movement by blocking unauthorized communication paths between SharePoint farm components and limiting enumeration capabilities across the infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility and traffic monitoring would likely have detected anomalous communication patterns and constrained the attacker's ability to establish covert command and control channels through SharePoint infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained data exfiltration by limiting outbound data transfer paths and reducing the volume of sensitive information that could be extracted from SharePoint repositories.
While ransomware deployment may still occur on initially compromised SharePoint assets, the blast radius would likely be significantly reduced with fewer connected systems and data repositories accessible for encryption.
Impact at a Glance
Affected Business Functions
- Document Management Systems
- Collaboration Platforms
- Intranet Services
- Business Process Workflows
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of corporate documents, employee collaboration data, business process information, and administrative credentials stored within SharePoint environments. Risk of unauthorized access to sensitive organizational content and intellectual property.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Inline IPS with Suricata signatures to detect and block CVE-2026-55040 and CVE-2026-63520 exploit attempts against SharePoint servers
- • Implement Zero Trust Segmentation to isolate SharePoint servers and prevent lateral movement through microsegmentation policies
- • Enable Multicloud Visibility & Control to monitor anomalous SharePoint admin enumeration activities and suspicious automation patterns
- • Configure Egress Security & Policy Enforcement to block unauthorized data exfiltration from SharePoint document libraries to external destinations
- • Establish East-West Traffic Security controls to monitor and restrict service-to-service communications within the SharePoint farm environment



