Skip to content
Tech News
← Back to articles

Hackers leverage new Microsoft SharePoint exploit in attacks

read original more articles
Why This Matters

The discovery and exploitation of the CVE-2026-55040 vulnerability in Microsoft SharePoint highlight the ongoing risks associated with unpatched enterprise software. As attackers rapidly weaponize proof-of-concept exploits, organizations must prioritize timely patching and security measures to prevent data breaches and unauthorized access. This incident underscores the importance of proactive cybersecurity defenses in protecting critical infrastructure and sensitive information.

Key Takeaways

A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks.

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.

Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.

"The authentication feature could be bypassed as this vulnerability allows impersonation," it said. "Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system."

A detailed technical write-up on CVE-2026-55040 was published by Rapid7 security researcher Stephen Fewer on Tuesday, together with a PoC exploit.

Earlier today, threat intelligence company Defused reported that Rapid7's exploit code has already been weaponized in attacks targeting its honeypots.

"Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned. "The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday."

Internet threat watchdog Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online. However, there is no information on how many of them are honeypots or have already been patched against this security flaw.

SharePoint servers exposed online (Shadowserver)

While Microsoft has labeled this security flaw as an attractive target for attackers, it has yet flag it as successfully exploited in the wild.

... continue reading