Attackers weaponize Microsoft SharePoint authentication-bypass flaw CVE-2026-55040 after public exploit release

Attackers are already using a newly published exploit to target Microsoft SharePoint servers, putting organizations with internet-exposed SharePoint at immediate risk. The flaw, CVE-2026-55040, is a critical authentication-bypass bug in SharePoint Enterprise Server 2016 and SharePoint Server 2019 that lets an unauthenticated attacker impersonate a site user or administrator through the JSON Web Token (JWT) validation pipeline. Microsoft patched it in July 2026, and Defused says the Rapid7 proof-of-concept was quickly seen hitting honeypots.
Why it matters: Organizations running on-premises SharePoint should treat this as urgent because public exploit code is already being used in the wild. Patch immediately and reduce exposure by restricting or proxying internet-facing SharePoint access, especially Central Administration.

Sources

Hackers target Microsoft SharePoint RCE chain with PoC exploit
Sergiu Gatlan 2026.08.26 96% relevant
This advances the same underlying event by reporting that attackers are no longer just exploiting CVE-2026-55040 alone, but are now probing and attempting to chain it with CVE-2026-63520 for SharePoint Server remote code execution after public PoC releases.
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
Ionut Arghire 2026.08.19 94% relevant
This source confirms CISA added the SharePoint flaw CVE-2026-55040 to KEV and is urging immediate patching, tying the earlier exploitation to a federal patch deadline.
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
info@thehackernews.com (The Hacker News) 2026.08.13 98% relevant
The article appears to cover the same underlying event: attackers exploiting a Microsoft SharePoint authentication-bypass flaw after a public proof-of-concept was released, updating that exploitation-focused story rather than introducing a separate incident.
SharePoint Vulnerability Exploited Shortly After PoC Release
Eduard Kovacs 2026.08.12 99% relevant
This is the same underlying event: active exploitation of Microsoft SharePoint CVE-2026-55040 after a public proof-of-concept was released. The article adds that Defused honeypots observed attacks beginning shortly after Rapid7 published technical details and a PoC, and notes a newly disclosed companion flaw, CVE-2026-63520, that could be chained for unauthenticated remote code execution.
Hackers leverage new Microsoft SharePoint exploit in attacks
Sergiu Gatlan 2026.08.12 100% relevant
This article establishes a distinct story around CVE-2026-55040: unlike the existing tracked SharePoint items on CVE-2026-45659 and CVE-2026-50522, this is a separate authentication-bypass flaw with new evidence that public PoC code has been weaponized in attacks.
← Back to all stories