A third party published CVE-2026-63520 before the planned date, and two public gadget chains now reach the same flaw by different routes. One signature will not cover both.
Reality
- Evidence72
- Adoption40
- Hype gap+5
- Incentives45
- Confidence70
Dinh Ho Anh Khoa's writeup turns CVE-2026-65660 into authenticated remote code execution on SharePoint 2016, 2019 and Subscription Edition. Microsoft's advisory scores the flaw 6.5 and calls it spoofing. NVD scores it 8.8.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence58
Only one of the 398 CVEs Microsoft fixed in August was confirmed exploited, and the SharePoint chain now hitting servers turns on a July patch, which puts exposure on cycle lag rather than on ranking.
Reality
- Evidence33
- Adoption44
- Hype gap+16
- Incentives56
- Confidence38
Attackers are forging tokens SharePoint accepts, then enumerating management APIs and probing Business Connectivity Services for the execution sink. BleepingComputer reports nobody has seen that last step land.
Reality
- Evidence55
- Adoption42
- Hype gap+18
- Incentives30
- Confidence48
CVE-2026-55040 was patched in July. Rapid7 published the technical details and a script on August 11, and Defused says its honeypots logged exploitation on August 12.
Reality
- Evidence58
- Adoption34
- Hype gap+12
- Incentives62
- Confidence57