Critical SharePoint Exploit Is Already Being Used in Attacks
Attackers are already using a public proof-of-concept exploit for a critical Microsoft SharePoint vulnerability tracked as CVE-2026-55040.
The attacks started shortly after Rapid7 published a technical analysis and working PoC on Tuesday. Threat intelligence company Defused says it detected attackers using Rapid7’s exploit against SharePoint honeypots within a day.
Microsoft has not officially marked CVE-2026-55040 as exploited in the wild.
SharePoint flaw allows authentication bypass
CVE-2026-55040 affects SharePoint’s JWT token validation pipeline and allows an unauthenticated attacker to bypass authentication.
An attacker who successfully exploits the vulnerability can impersonate a SharePoint user or administrator. This could allow access to files and enable unauthorized data modifications, although Microsoft says the flaw does not directly affect system availability.
The vulnerability affects SharePoint Enterprise Server 2016 and SharePoint Server 2019. Microsoft patched it during its July 2026 security updates alongside hundreds of other vulnerabilities. Microsoft recently addressed around 400 security flaws in its Patch Tuesday updates.
Rapid7 PoC quickly appears in attacks
Rapid7 researcher Stephen Fewer published the technical analysis and proof-of-concept exploit code for CVE-2026-55040.
Defused later observed attackers using the public exploit against its SharePoint honeypots. The activity shows how quickly attackers can adopt publicly available exploit code after researchers publish it.
CISA urges organizations to secure SharePoint
CISA warned defenders about potential CVE-2026-55040 attacks on July 15.
Organizations should avoid exposing SharePoint servers directly to the internet unless necessary. CISA also recommends blocking external access to SharePoint Central Administration and restricting farm and database communications to systems that require them.
Internet-facing SharePoint deployments should also sit behind a Layer 7 reverse proxy or similar application-layer security control.
CVE-2026-55040 isn’t the only SharePoint security threat. CISA has also confirmed that another SharePoint flaw is being used in ransomware attacks. Separately, the newly discovered ShieldBreak zero-day exploit can affect fully patched Windows systems.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages