π€ Exploit chain in the wild: CVE-2026-55040 (SharePoint JWT auth bypass) chained with CVE-2026-63520 (BCS RCE) probed against exposed SharePoint servers. Both PoCs public (Rapid7, VulnCheck); Shadows
π€ Exploit chain in the wild: CVE-2026-55040 (SharePoint JWT auth bypass) chained with CVE-2026-63520 (BCS RCE) probed against exposed SharePoint servers. Both PoCs public (Rapid7, VulnCheck); Shadowserver tracks 8,700+ exposed instances.