Attackers are now actively exploiting a critical vulnerability in Microsoft SharePoint, highlighting how quickly threat actors can move once working exploit code becomes publicly available.
The vulnerability, tracked as CVE-2026-55040 and rated 9.1 out of 10 for severity, affects SharePoint’s authentication process. Microsoft patched the flaw as part of its July 2026 security updates, but the risk has increased significantly after security firm Rapid7 published a proof-of-concept (PoC) exploit.
The vulnerability can allow an unauthenticated remote attacker to bypass SharePoint authentication and impersonate a legitimate user, potentially including an administrator. From there, an attacker could access files, modify data and perform actions with the privileges of the impersonated account.
The technical issue is linked to weaknesses in SharePoint’s JWT token validation process. Researchers found that attackers can manipulate elements such as JWT headers, certificate thumbprints and token validation mechanisms to create a forged authentication token that SharePoint accepts as legitimate.
Rapid7’s publicly released Python-based PoC demonstrates how the vulnerability can be exploited. The tool can generate a forged token and use it to interact with a target’s domain controller, enumerate users and identify potential SharePoint administrators.
What makes the situation particularly concerning is how quickly exploitation followed the public release. According to KEVIntel telemetry, 12 exploitation attempts had been observed since July 19, with eight of those attempts occurring on August 12 and 13 around the time the public PoC became available. The activity involved eight unique IP addresses across Hong Kong, Japan, the Netherlands, Taiwan and the United States. Researchers have not yet attributed the activity to a specific threat actor or confirmed the attackers’ ultimate objectives.
This is also not an isolated SharePoint incident. CVE-2026-55040 is reportedly the fifth SharePoint vulnerability exploited in the wild this year. Other recently exploited flaws include CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522.
The situation shows why SharePoint continues to be an attractive target. For many organizations, it is deeply connected to corporate documents, collaboration, identities and sensitive business information. An authentication bypass therefore creates a much bigger risk than a typical application vulnerability because successful exploitation could provide attackers with a path into valuable organizational data.
Organizations using affected SharePoint environments should make sure Microsoft’s July 2026 security updates have been applied and should not assume that patching alone closes the investigation. Security teams should also review authentication logs, administrator activity, unexpected account enumeration, permission changes and unusual file access for signs of compromise.
The bigger lesson is the shrinking gap between vulnerability disclosure and exploitation. Once reliable proof-of-concept code becomes public, attackers can move extremely quickly. For security teams, knowing which systems are exposed, prioritizing vulnerabilities that are actively being exploited and looking for signs of abuse can be just as important as maintaining a regular patching schedule.
Let’s refine your stalking skills; go through our Instagram and LinkedIn.