Attackers are now testing a Microsoft SharePoint exploit chain that combines an authentication bypass with a remote code execution flaw, according to BleepingComputer, which cites threat intelligence company Defused. The activity targets unpatched SharePoint servers and follows the release of public proof-of-concept code for both vulnerabilities. The first flaw, CVE-2026-55040, is described as an authentication bypass in SharePoint’s JWT token validation pipeline. BleepingComputer reports that an attacker without privileges could use it to perform operations as a SharePoint site user or administrator. The second flaw, CVE-2026-63520, affects SharePoint’s Business Connectivity Services. According to the report, an unauthenticated attacker can chain it after CVE-2026-55040 to pursue remote code execution on a targeted SharePoint Server. The timing matters because exploit code is now public for both parts of the chain. BleepingComputer says Rapid7 security researcher Stephen Fewer released proof-of-concept code for CVE-2026-55040 on August 11, and VulnCheck vulnerability researcher Jonathan Peterson released proof-of-concept code for CVE-2026-63520 on August 24. Defused reported one day after the first proof-of-concept appeared that Rapid7’s code had already been weaponized in attacks, according to BleepingComputer. Roughly two weeks later, on August 25, Defused said its honeypots were seeing probes for the combined SharePoint chain, including use of the JWT bypass followed by administrator enumeration and testing of the Business Data Catalog path tied to CVE-2026-63520. Defused had not observed code execution in those honeypots, BleepingComputer reports. The exposure base is not trivial. BleepingComputer cites the Shadowserver Foundation as tracking more than 8,700 Microsoft SharePoint servers exposed to the internet. The report notes that it is not clear how many of those are honeypots or how many have already been secured against these flaws. CISA has already pushed defenders to act on at least part of the chain. According to BleepingComputer, the U.S. Cybersecurity and Infrastructure Security Agency ordered federal agencies and network defenders on August 18 to secure SharePoint servers against ongoing CVE-2026-55040 attacks. Microsoft has described CVE-2026-63520 as an attractive target for threat actors, but has not yet tagged that flaw as exploited in the wild, the report says. The broader SharePoint backdrop is already active. BleepingComputer reports that CISA warned on July 15 about active exploitation of three other SharePoint vulnerabilities — CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 — against internet-exposed on-premises SharePoint Server instances. CISA also confirmed that CVE-2026-45659, a SharePoint remote code execution vulnerability flagged as exploited since early July, is now being used in ransomware attacks. For operators, the immediate message is narrower than “SharePoint is compromised”: the provided evidence shows probing and weaponization around CVE-2026-55040, public exploit availability for both parts of the chain, and honeypot activity against the combined path. It does not establish that CVE-2026-63520 has been broadly exploited in the wild, and BleepingComputer specifically notes Microsoft has not tagged it that way. Who benefits: Attackers benefit from public exploit code and from exposed, unpatched SharePoint servers. Defenders benefit from early honeypot reporting that identifies the chain before confirmed code execution is observed in that environment. Who's exposed: Organizations running internet-exposed on-premises Microsoft SharePoint Server instances are the clearest exposed group. The provided reports do not say how many of the more than 8,700 exposed servers tracked by Shadowserver are vulnerable or already secured.