Security researchers have identified a dangerous two-stage exploit chain targeting Microsoft SharePoint servers that combines an authentication bypass, CVE-2026-55040, with a remote code execution flaw, CVE-2026-63520.
The authentication bypass, which carries a CVSS score of 9.1, allows unauthenticated attackers to impersonate privileged users, while the second flaw enables arbitrary code execution via Business Connectivity Services.
Threat-intelligence firm Defused reported observing active probing of these vulnerabilities on August 25, urging organizations to immediately apply the security updates released by Microsoft in July and August 2026.