August 2026 research has identified two high-impact authentication and execution vectors targeting Microsoft's ecosystem. Rapid7 utilized AI-driven automation to uncover a SharePoint unauthenticated RCE chain (CVE-2026-55040 and CVE-2026-63520), leveraging JWT token forgery and unsafe .NET type instantiation in Business Connectivity Services. Concurrently, SpecterOps identified 'Pass-the-Passkey,' a mechanism to bypass Multi-Factor Authentication (MFA) within Windows and Entra ID environments. These vulnerabilities represent a significant shift in exploit methodology, particularly with the integration of AI in discovering complex logic flaws. Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face immediate RCE risk, while modern cloud-native identities are vulnerable to MFA circumvention.
-
Vulnerability Overview: Dual-Vector Attack Surface
- 'Pass-ta-key' targeting on-premises SharePoint infrastructure via unauthenticated RCE.
- 'Pass-the-Passkey' targeting Windows and Entra ID identity perimeters to circumvent MFA.
- Convergence of legacy on-premises exploitation and modern cloud-native identity bypass.
-
Technical Deep Dive: SharePoint RCE Chain
- CVE-2026-55040: A critical JWT authentication bypass (CVSS 9.1) enabling administrative token forgery through a four-stage weakness chain.
- CVE-2026-63520: An unsafe .NET type instantiation flaw in Business Connectivity Services (CVSS 8.1) facilitating remote code execution.
- Discovery achieved through massive-scale AI agent automation involving 80,000 tool calls and 256 prompts.
-
Technical Deep Dive: Identity Perimeter Bypass
- 'Pass-the-Passkey' exploits complex logic flaws within the Windows and Entra ID authentication handshake.
- Capability to bypass modern Multi-Factor Authentication (MFA) requirements for authenticated sessions.
- Direct threat to Zero Trust architectures and modern identity-centric security models.
-
Threat Landscape & Impact
- Active exploitation confirmed following the public release of Proof-of-Concept (PoC) exploits.
- Potential correlation with Lazarus Group-style Advanced Persistent Threat (APT) activity.
- Immediate critical risk to SharePoint Server 2016, 2019, and Subscription Edition deployments.
-
Mitigation & Defensive Strategy
- Prioritize deployment of Microsoft August 2026 security patches across all on-premises SharePoint environments.
- Monitor SharePoint logs for forged JWT tokens and unauthorized administrative impersonation.
- Audit Entra ID and Windows authentication telemetry for anomalous MFA bypass indicators.
Related posts
- Cybersecurity News — Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA
- gbhackers.com — Pass-the-Passkey Attack Exploits Windows and Entra ID to Bypass MFA
- datawater.com — Pass-ta-key for SharePoint: CVE-2026-55040 + CVE-2026-63520 — Four JWT Weaknesses, No Credentials, Become Any User, Then Full RCE — AI Agent Found It Across 80,000 Tool Calls and Also Cheated — Full Chain Patchable Today
- Expert In the Cloud — SharePoint Authentication Bypassed
- techjacksolutions.com — CVE-2025-53770: Critical SharePoint RCE Actively Exploited Following Rapid7 PoC Release
- Specterops
- Captechgroup
- Sec
- Easternherald
- Cybercalm
- Dark Reading — Flaws in Passkey Implementation Show Old Attacks Still Work