Hackers leverage new Microsoft SharePoint exploit in attacks
Reported exploitedMicrosoftOur summary
Cybercriminals have begun deploying a proof-of-concept exploit for the critical authentication bypass flaw tracked as CVE-2026-55040, which affects Microsoft SharePoint Server. Published by Rapid7, the code allows unauthorized users to impersonate valid identities within SharePoint environments by exploiting weaknesses in the JWT token validation process. Although Microsoft patched this vulnerability during the July 2026 Patch Tuesday cycle for SharePoint Enterprise Server 2016 and SharePoint Server 2019, threat intelligence firm Defused confirmed that attackers are actively using the tool against exposed systems.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.