Proof‑of‑Concept Exploit Chains Two SharePoint Vulnerabilities (CVE‑2026‑55040 & CVE‑2026‑63520) for Remote Code Execution
What Happened — Researchers disclosed a public PoC that chains an authentication‑bypass flaw (CVE‑2026‑55040) with a Business Connectivity Services flaw (CVE‑2026‑63520) to achieve remote code execution on unpatched Microsoft SharePoint servers. Within days of the first PoC’s release, threat intel firm Defused observed weaponized attacks against its honeypots.
Why It Matters for Compliance & Audit Readiness
- The chain bypasses authentication and escalates to full code execution, directly testing the effectiveness of your SOC 2 Access Control policies (CC6.1, CC6.2).
- Continuous evidence of patch management and privileged‑access monitoring is essential to demonstrate due diligence during a SOC 2 audit.
- Leveraging Verisq’s SOC2 Access Controls capability provides automated control mapping and audit‑ready logs of remediation actions.
Who Is Affected — Enterprises that run on‑premises or internet‑exposed SharePoint Server instances across all verticals (finance, healthcare, government, etc.).
Recommended Actions
- Apply Microsoft’s security updates for CVE‑2026‑55040 and CVE‑2026‑63520 immediately.
- Verify JWT token validation hardening and restrict BCS permissions to the minimum required.
- Document the patch‑deployment process and collect evidence (e.g., patch‑install logs, configuration snapshots) to satisfy SOC 2 access‑control audit requirements. Source: BleepingComputer
Technical Notes
- Attack vector: Vulnerability exploit (authentication bypass → BCS RCE).
- CVEs: CVE‑2026‑55040 (JWT auth bypass), CVE‑2026‑63520 (BCS remote code execution).
- Public PoCs: Rapid7 (CVE‑2026‑55040) and VulnCheck (CVE‑2026‑63520).
- Impact: Potential full server compromise; no confirmed data exfiltration yet. Source: BleepingComputer