Cybercriminals are actively exploiting a critical vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the public release of a proof-of-concept (PoC) exploit. This flaw, which Microsoft addressed in its July 2026 Patch Tuesday updates, allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access and data manipulation.
The vulnerability arises from weaknesses in SharePoint’s authentication processes, enabling malicious actors to impersonate legitimate users. Exploiting this flaw could grant attackers the ability to disclose files and modify data, though it does not impact system availability. The exploitation involves crafting a JSON Web Token (JWT) that the system misinterprets as valid, thereby granting unauthorized access.
Security researchers have observed that attackers are leveraging a PoC exploit released by Rapid7. This exploit takes advantage of multiple issues within SharePoint’s JWT token validation pipeline, allowing unauthenticated remote attackers to forge valid tokens and impersonate any SharePoint site user. The exploitation chain includes manipulating token headers and signatures to deceive the system into granting access.
Telemetry data indicates a surge in exploitation attempts, with 12 recorded incidents since July 19, 2026. Notably, eight of these attempts occurred on August 12 and 13, 2026, suggesting that the release of the PoC has significantly contributed to the uptick in attacks. These attempts have originated from multiple countries, including Hong Kong, Japan, the Netherlands, Taiwan, and the United States.
Given the critical nature of this vulnerability and the active exploitation in the wild, it is imperative for organizations utilizing SharePoint to apply the latest security patches promptly. Ensuring that systems are up-to-date is crucial to mitigating the risk posed by this authentication bypass flaw.
This incident underscores the importance of timely patch management and vigilance in monitoring for emerging threats. Organizations should not only apply patches as they become available but also implement robust monitoring systems to detect and respond to exploitation attempts promptly. The rapid weaponization of vulnerabilities following public disclosures highlights the need for a proactive and comprehensive approach to cybersecurity.