Active wild exploitation targeting on-premises document management servers has accelerated following the public release of a functional proof of concept exploit script. Threat actors are utilizing the public exploit code to bypass authentication handlers and execute arbitrary remote code on vulnerable servers.
The attack activity targets Microsoft SharePoint Server installations by chaining authentication bypass flaw CVE-2026-55040 with remote code execution vulnerability CVE-2026-63520. By forging JWT tokens, an unauthenticated remote attacker impersonates administrative site accounts and triggers backend code execution modules. Threat intelligence sensors confirm active exploitation attempts targeting public-facing SharePoint farms.
Subverting central document repositories compromises corporate identity and file security boundaries. Armed with administrative access over SharePoint farms, threat actors can exfiltrate proprietary document stores, modify site data, and move horizontally into adjacent active directory networks.
– Apply Microsoft July and August 2026 cumulative security patches across all on-premises SharePoint Server farms immediately.
– Inspect web server ingress logs for anomalous HTTP requests targeting JWT token validation endpoints.
– Rotate all administrative session keys and certificate parameters associated with SharePoint site collections.
– Isolate SharePoint web portals behind pre-authenticated zero trust gateways to restrict direct public internet access.
Enterprise document portal defense requires rapid patch deployment combined with perimeter access controls to ensure collaboration servers are protected from public exploit chains. #CodeDefence #Microsoft #SharePoint #RCE #AuthBypass #Rapid7 #AppSec #PatchManagement
/
