← Back to Daily Briefing (#MultiAgentSystems)

August 2026 research has identified two high-impact authentication and execution vectors targeting Microsoft's ecosystem. Rapid7 utilized AI-driven automation to uncover a SharePoint unauthenticated RCE chain (CVE-2026-55040 and CVE-2026-63520), leveraging JWT token forgery and unsafe .NET type instantiation in Business Connectivity Services. Concurrently, SpecterOps identified 'Pass-the-Passkey,' a mechanism to bypass Multi-Factor Authentication (MFA) within Windows and Entra ID environments. These vulnerabilities represent a significant shift in exploit methodology, particularly with the integration of AI in discovering complex logic flaws. Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face immediate RCE risk, while modern cloud-native identities are vulnerable to MFA circumvention.

  • Vulnerability Overview: Dual-Vector Attack Surface

    • 'Pass-ta-key' targeting on-premises SharePoint infrastructure via unauthenticated RCE.
    • 'Pass-the-Passkey' targeting Windows and Entra ID identity perimeters to circumvent MFA.
    • Convergence of legacy on-premises exploitation and modern cloud-native identity bypass.
  • Technical Deep Dive: SharePoint RCE Chain

    • CVE-2026-55040: A critical JWT authentication bypass (CVSS 9.1) enabling administrative token forgery through a four-stage weakness chain.
    • CVE-2026-63520: An unsafe .NET type instantiation flaw in Business Connectivity Services (CVSS 8.1) facilitating remote code execution.
    • Discovery achieved through massive-scale AI agent automation involving 80,000 tool calls and 256 prompts.
  • Technical Deep Dive: Identity Perimeter Bypass

    • 'Pass-the-Passkey' exploits complex logic flaws within the Windows and Entra ID authentication handshake.
    • Capability to bypass modern Multi-Factor Authentication (MFA) requirements for authenticated sessions.
    • Direct threat to Zero Trust architectures and modern identity-centric security models.
  • Threat Landscape & Impact

    • Active exploitation confirmed following the public release of Proof-of-Concept (PoC) exploits.
    • Potential correlation with Lazarus Group-style Advanced Persistent Threat (APT) activity.
    • Immediate critical risk to SharePoint Server 2016, 2019, and Subscription Edition deployments.
  • Mitigation & Defensive Strategy

    • Prioritize deployment of Microsoft August 2026 security patches across all on-premises SharePoint environments.
    • Monitor SharePoint logs for forged JWT tokens and unauthorized administrative impersonation.
    • Audit Entra ID and Windows authentication telemetry for anomalous MFA bypass indicators.

Related posts

  1. Cybersecurity News — Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
  2. gbhackers.com — Pass-the-Passkey Attack Exploits Windows and Entra ID to Bypass MFA
  3. datawater.com — Pass-ta-key for SharePoint: CVE-2026-55040 + CVE-2026-63520 — Four JWT Weaknesses, No Credentials, Become Any User, Then Full RCE — AI Agent Found It Across 80,000 Tool Calls and Also Cheated — Full Chain Patchable Today
  4. Expert In the Cloud — SharePoint Authentication Bypassed
  5. techjacksolutions.com — CVE-2025-53770: Critical SharePoint RCE Actively Exploited Following Rapid7 PoC Release
  6. Specterops
  7. Captechgroup
  8. Sec
  9. Easternherald
  10. Cybercalm
  11. Dark Reading — Flaws in Passkey Implementation Show Old Attacks Still Work

LINK COPIED TO CLIPBOARD