SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Brief
Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators.
Attackers started exploiting CVE-2026-55040 (CVSS score of 9. 1), a critical SharePoint authentication bypass patched in July, within days of Rapid7 releasing a public proof-of-concept on August 12. The vulnerability allows an unauthenticated attacker impersonate any SharePoint user or administrator without valid credentials.
Microsoft patched it in July’s Patch Tuesday, anyone who hasn’t applied that update is directly exposed.
CVE-2026-55040 is a critical SharePoint authentication bypass. An unauthenticated attacker can exploit weaknesses in JWT validation to forge tokens and impersonate any SharePoint user, including administrators.
