Critical Microsoft SharePoint Exploit Chain Exposed
Two distinct Microsoft SharePoint vulnerabilities have seamlessly merged to form a devastating, fully operational exploit chain. This formidable combination empowers malicious actors to execute arbitrary code remotely on a targeted server, completely bypassing the need for a legitimate user account. The initial vulnerability facilitates seamless impersonation, allowing an attacker to masquerade as a standard user or a privileged administrator. Subsequently, the secondary flaw leverages these illegitimately acquired permissions to execute destructive Windows commands. The astute cybersecurity specialists at VulnCheck successfully assembled this functional exploit chain, conclusively demonstrating that at least two distinct exploitation pathways exist for the CVE-2026-63520 vulnerability.
The Anatomy of the Impersonation Exploit
The insidious CVE-2026-55040 vulnerability, possessing a critical severity score of 9.1, serves as the initial link in this destructive chain. This specific error resides deep within the mechanism responsible for verifying SharePoint JWT tokens. As the diligent specialists at Rapid7 discovered, multiple concurrent flaws exist in how SharePoint validates these tokens. These compounding deficiencies allow an unauthenticated, remote user to meticulously forge a fraudulent JWT. Consequently, the attacker can seamlessly operate under the guise of any selected SharePoint user, including the site administrator.
Crucially, CVE-2026-55040 does not independently execute code on the compromised server. However, it flawlessly provides the elevated privileges absolutely essential for deploying the second half of the exploit chain.
Executing Arbitrary Code via Business Connectivity Services
The subsequent vulnerability, designated CVE-2026-63520 with a severity score of 8.1, directly affects the Business Connectivity Services. SharePoint relies upon this specific service to integrate external data sources. Alarmingly, this service possessed the capability to instantiate .NET types specified within a BDC model without conducting rigorous verification procedures.
An attacker, now armed with the requisite privileges obtained via the initial exploit, could maliciously upload a meticulously crafted model. This action effectively forces SharePoint to execute arbitrary commands utilizing the elevated privileges of the service account operating the site.
Fascinatingly, Rapid7 and VulnCheck employed entirely different methodologies to compel the system to execute their code. The Rapid7 variant utilized a BDC system of the Database type alongside an ObjectDataProvider-based chain. Conversely, VulnCheck opted for DotNetAssembly and LosFormatter. These two independent variations unequivocally demonstrate that the vulnerable mechanism is not inextricably linked to a single, specific technique. Indeed, other, yet-undiscovered exploitation methods might also prove viable.
The Escalating Threat Landscape
The lethal combination of these two errors generates an exceptionally perilous scenario. CVE-2026-55040 completely neutralizes the authentication requirement, paving the way for CVE-2026-63520 to execute arbitrary code with impunity. VulnCheck conservatively estimates that at least 8,500 vulnerable SharePoint servers remain accessible via the internet, even after meticulously filtering out honeypots and duplicate nodes from their comprehensive sample. The specialists successfully prepared a fully functional variant of the exploit chain long before publishing their detailed technical analysis.
Exploitation Beyond the Laboratory
Alarmingly, the initial component of this exploit has already transcended theoretical laboratory demonstrations. On August 18th, the esteemed American CISA agency officially appended CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) catalog following confirmed reports of active attacks. For American federal agencies, the strict deadline mandated for installing the necessary remediations expired on August 21st. As of August 26th, however, no official confirmation exists indicating that malicious actors are actively exploiting CVE-2026-63520 in real-world assaults.
The Unconventional Discovery Process
The narrative surrounding the discovery of these flaws is equally remarkable. Rapid7 initiated the project as a novel experiment, seeking to utilize publicly available AI models to thoroughly analyze a proprietary, closed-source corporate product. An entirely autonomous approach ultimately proved unreliable. Consequently, the specialists continuously verified the agent’s conclusions and meticulously guided the search parameters.
Before successfully isolating the functional chain, the AI system operated for approximately 120 hours over 24 days. It conducted 96 distinct sessions and executed roughly 80,000 tool calls. Throughout this groundbreaking experiment, human operators submitted 256 specific requests to the agent. They uncovered CVE-2026-55040 in early March, with CVE-2026-63520 revealing itself approximately two weeks later.
Patching and Mitigation Strategies
Initially, the researchers prepared this potent exploit chain for the prestigious Pwn2Own Berlin competition. Rapid7 responsibly disclosed their findings to Microsoft on May 18th. By May 20th, the developer officially acknowledged the profound issues and astutely decided to partition the remediation across two distinct update cycles. Microsoft definitively closed the authentication bypass in July and addressed the remote code execution vulnerability in August.
Rapid7 initially planned to embargo the intricate technical details of CVE-2026-63520 for 30 days. However, following VulnCheck’s publication of their comprehensive analysis, Rapid7 prematurely disclosed their proprietary variant on August 24th.
Applying the Necessary Updates
Microsoft released the crucial July updates specifically for CVE-2026-55040. The SharePoint Server Subscription Edition received build 16.0.19725.20434 via KB5002882. Installing only the July update remains dangerously insufficient, as the second half of the exploit chain remained vulnerable until the August release.
Microsoft successfully neutralized CVE-2026-63520 on August 11th. For the SharePoint Server Subscription Edition, the remediated build is 16.0.19725.20522 from KB5002893. Furthermore, the August Subscription Edition update alters default behaviors. It no longer imports BDC models directly from files and strictly permits only explicitly authorized .NET types, thereby significantly restricting the dangerous mechanism.
Administrators managing local SharePoint servers must now meticulously verify the installation of both comprehensive patch sets. Relying solely upon the remediation for CVE-2026-55040 is unacceptable. One crucial segment of this chain is already enduring active exploitation in real-world attacks. Multiple functional exploitation methods for the second vulnerability are now public knowledge, alongside the intricate details of the entire sequence. For unpatched servers lingering on the open internet, the window of safety between the publication of technical details and the emergence of ready-made exploit tools has effectively slammed shut.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.