A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks.
Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
"The authentication feature could be bypassed as this vulnerability allows impersonation," it said. "Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system."
A detailed technical write-up on CVE-2026-55040 was published by Rapid7 security researcher Stephen Fewer on Tuesday, together with a PoC exploit.
Earlier today, threat intelligence company Defused reported that Rapid7's exploit code has already been weaponized in attacks targeting its honeypots.
"Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned. "The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday."
Internet threat watchdog Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online. However, there is no information on how many of them are honeypots or have already been patched against this security flaw.
SharePoint servers exposed online (Shadowserver)
While Microsoft has labeled this security flaw as an attractive target for attackers, it has yet flag it as successfully exploited in the wild.
... continue reading