Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server, according to a Monday blog post by researchers at VulnCheck.
The sequence involves a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed Aug. 11 by researchers at cybersecurity firm Rapid7.
Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful, To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520.
“The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,” Vulncheck researchers said in their post.
Exploitation was confirmed against the first part of the attack sequence within days of Rapid7’s initial analysis. VulnCheck added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on Aug. 12, and the Cybersecurity and Infrastructure Security Agency added the flaw to its catalog on Aug. 18.
VulnCheck researchers found about 8,500 SharePoint servers were visible online.
Researchers from Defused said Tuesday they can already see probing activity against its honeypots involving the chained sequence, according to a post on X.
CISA previously warned in July that multiple vulnerabilities in SharePoint were facing exploitation.