Threat actors are actively exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication bypass flaw with a CVSS score of 9.1, after public proof-of-concept code was released. The vulnerability, patched by Microsoft in July 2026, affects SharePoint Server Subscription Edition and allows unauthenticated attackers to forge JWTs, bypass authentication, and impersonate any SharePoint user, including administrators. Researchers said the bug chain stems from multiple weaknesses in SharePoint’s JWT validation pipeline, including acceptance of an outer token using alg: none and failures to properly verify certificate trust and token signatures.
Security researchers and honeypot operators reported a sharp rise in exploitation attempts immediately after the PoC became public, with telemetry showing 12 attempts since July 19 and most activity concentrated on August 12 and 13. Successful attacks can expose documents, enable data modification across a SharePoint farm, and provide a foothold for broader compromise of connected Microsoft 365 environments, increasing urgency for organizations to apply Microsoft’s patch and review SharePoint access for signs of abuse.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Eight of the 12 recorded exploitation attempts occurred on August 12 and 13, 2026, indicating a surge in abuse after the proof-of-concept became public. Researchers also observed attackers using Rapid7's exploit against SharePoint honeypots.
Rapid7 released a Python-based public proof-of-concept for CVE-2026-55040 on GitHub on August 12, 2026. The PoC demonstrated forging JWTs to query a target's domain controller, enumerate users by SID, and locate a SharePoint site administrator.
Rapid7 identified CVE-2026-63520 as a second SharePoint vulnerability that can be chained with CVE-2026-55040 to achieve unauthenticated remote code execution. Microsoft patched CVE-2026-63520 in the August 2026 Patch Tuesday, and no active exploitation had been reported at the time.
KEVIntel telemetry recorded exploitation attempts targeting CVE-2026-55040 starting on July 19, 2026. The reporting later counted 12 attempts from eight IP addresses across multiple countries.
Microsoft patched CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, in its July 2026 Patch Tuesday updates. The flaw could let unauthenticated attackers forge JWTs, impersonate users or administrators, read files, and modify data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecyberveille.ch
Open sourcekevintel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.