Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server, according to a Monday blog post by researchers at VulnCheck.

The sequence involves a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed on Aug. 11 by researchers at cybersecurity firm Rapid7. 

Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful. To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520. 

“The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,” Vulncheck researchers said in their post

Exploitation was confirmed against the first part of the attack sequence within days of Rapid7’s initial analysis. VulnCheck added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on Aug. 12, and the Cybersecurity and Infrastructure Security Agency added the flaw to its catalog on Aug. 18. 

Microsoft addressed CVE-2026-55040 in its July security update, and CVE-2026-63520 in its August update, according to a spokesperson. The company said if organizations install those patches and follow its SharePoint software update deployment guidance document, they should be protected.

According to Microsoft, it was not aware of any exploit activity at the time of publishing the respective CVEs. The company thanked Rapid7 for reporting the flaws via a coordinated disclosure process.

VulnCheck researchers found about 8,500 SharePoint servers were visible online. 

Researchers from Defused said Tuesday they can already see probing activity against its honeypots involving the chained sequence, according to a post on X

CISA previously warned in July that multiple vulnerabilities in SharePoint were facing exploitation.

Editor’s note: Updates with comment from Microsoft.