BLUF: Active exploitation is underway targeting on-premises Microsoft SharePoint servers using a chained exploit. By chaining a JWT token authentication bypass (CVE-2026-55040) with a Business Connectivity Services RCE flaw (CVE-2026-63520), attackers can achieve unauthenticated remote code execution.
A public PoC was released on August 12, 2026, and this chain has been added to the CISA KEV list. Exploit attempts have spiked globally.
⚠️ Affected Products:
- SharePoint Enterprise Server 2016 (< 16.0.5561.1001)
- SharePoint Server 2019 (< 16.0.10417.20175)
- SharePoint Server Subscription Edition (< 16.0.19725.20434)
Note: While currently unattributed, related SharePoint campaigns have historically been linked to China-nexus actors like Storm-2603 and APT27.
🔍 The Attack Chain & Behavioral IOCs
There are no static IOCs (IPs, hashes, or domains) reliable for this campaign. Defenders must hunt for the following behavioral chain:
- Reconnaissance: Attacker enumerates AD SIDs or UPNs (via LDAP, MS Graph, or SharePoint user-picker).
- Auth Bypass (CVE-2026-55040): Attacker forges a JWT session token to impersonate the targeted user. Look for claims authentication with alg: none or missing issuer validation.
- Privilege Mapping: Burst enumeration of domain permission groups and SharePoint content repos within 10 minutes of auth.
- Lateral Movement Staging: Domain trust discovery (LDAP trustedDomain queries) within 1 hour of the forged session.
- Execution/Persistence (CVE-2026-63520): Outbound HTTP/S to unknown external URLs, or web shell/IIS component deployment on the SharePoint server.
🛠️ Hunting & Detection Rules
1️⃣ JWT Forgery Anomaly (Direct Exploit)
Target Logs: SharePoint STS Audit Logs / ULS Logs
Detection Logic: Filter for ClaimsAuthentication events. Flag any session where the JWT algorithm is explicitly set to none, OR where issuer validation is logged as false or is completely missing/null.
2️⃣ Recon & Auth Chaining (Precondition)
Target Logs: Azure AD Audit Logs / MS Graph + SharePoint STS
Detection Logic: Monitor for an actor performing directory recon (e.g., "Search users", "Get user"). Cross-reference the target of that search with your SharePoint Claims Auth logs. Alert if that specific targeted user successfully authenticates via Claims Auth within 5 minutes of the recon event.
3️⃣ Burst Permission Discovery (Post-Exploitation)
Target Logs: SharePoint ULS Logs
Detection Logic: Baseline your ClaimsAuthentication timestamps. Alert if the authenticated user triggers 5 or more enumeration actions (e.g., GroupMembershipEnum, SiteContentSearch, DocumentLibraryBulkRead) within 10 minutes of their initial login.
🛡️ Patch Immediately: Apply the August 2026 Patch Tuesday updates to all on-prem SharePoint environments.
External Link
Platform
You are about to visit:
https://example.comThis will open in a new tab. Make sure you trust this link.