Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Reported exploitedMicrosoft SharePointOur summary
Threat actors have begun actively exploiting a critical vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the public release of proof-of-concept code by Rapid7. This flaw enables remote unauthenticated attackers to bypass authentication mechanisms by manipulating the JWT token validation process, potentially allowing them to access sensitive files or modify data. While Microsoft had previously issued a fix during its July 2026 Patch Tuesday cycle, recent intelligence indicates that adversaries are now leveraging the available exploits against honeypots and live systems.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.