CVE Tools

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker NewsBy The Hacker News

Reported exploitedMicrosoft SharePoint

Our summary

Microsoft is actively addressing CVE-2026-55040, a critical authentication bypass in SharePoint that allows unauthenticated attackers to forge JWTs and impersonate administrators or site users. Following the release of a public proof-of-concept by Rapid7 this week, threat actors have begun exploiting the vulnerability, which was patched in Microsoft's July 2026 Patch Tuesday update. With a CVSS score of 9.1, the flaw stems from weak token validation logic that enables file disclosure and data modification without affecting system availability. Administrators should immediately apply the latest updates to prevent unauthorized access.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store