CVE Tools

Hackers leverage new Microsoft SharePoint exploit in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedMicrosoft

Our summary

Cybercriminals have begun deploying a proof-of-concept exploit for the critical authentication bypass flaw tracked as CVE-2026-55040, which affects Microsoft SharePoint Server. Published by Rapid7, the code allows unauthorized users to impersonate valid identities within SharePoint environments by exploiting weaknesses in the JWT token validation process. Although Microsoft patched this vulnerability during the July 2026 Patch Tuesday cycle for SharePoint Enterprise Server 2016 and SharePoint Server 2019, threat intelligence firm Defused confirmed that attackers are actively using the tool against exposed systems.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store