CISA Flags Critical Microsoft SharePoint Authentication Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has recently added a significant Microsoft SharePoint authentication vulnerability, identified as CVE-2026-55040, to its Known Exploited Vulnerabilities (KEV) catalog. This move underscores the urgency for organizations to address this flaw, which is currently being actively exploited.

CVE-2026-55040 pertains to a weakness in SharePoint’s authentication mechanism, specifically linked to CWE-1390. This flaw allows unauthenticated attackers to bypass security features remotely, posing a substantial risk to on-premises SharePoint environments. Notably, SharePoint Online remains unaffected by this issue.

Technical analyses indicate that the vulnerability affects the JSON Web Token (JWT) validation process within SharePoint. Exploiting this flaw, attackers can forge authentication tokens that SharePoint erroneously accepts as valid. This manipulation enables them to impersonate legitimate users, including administrators, granting unauthorized access to sensitive documents, collaboration sites, configuration data, and administrative functions without the need for legitimate credentials.

The affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft addressed this vulnerability in its July 2026 security updates. However, organizations that have delayed applying these patches are now at heightened risk, especially with the public availability of proof-of-concept exploit code.

In response, CISA added CVE-2026-55040 to its KEV catalog on August 18, 2026, setting a remediation deadline of August 21, 2026. While the agency’s advisory does not explicitly mention ransomware exploitation, the inclusion in the KEV catalog signals the critical nature of this vulnerability and the necessity for immediate action.

Organizations are strongly advised to implement Microsoft’s security updates and mitigations without delay, prioritizing externally accessible SharePoint servers. It’s crucial for administrators to ensure that updates are fully deployed across all servers within a SharePoint farm and to complete any required post-installation configurations. Incomplete patching can leave systems vulnerable.

Additionally, security teams should conduct thorough reviews of SharePoint and identity logs to detect any signs of token forgery or unauthorized administrative access. Indicators of compromise may include unexpected service-to-service authentication events, unusual administrator logins, unauthorized account changes, abnormal access to sensitive sites, and network traffic from untrusted sources targeting SharePoint endpoints.

Given the potential for attackers to appear as trusted users in logs due to token forgery, meticulous log analysis and forensic investigations are as vital as applying the necessary patches. CISA recommends that organizations adhere to vendor instructions, comply with Binding Operational Directive 26-04 for risk-based patching, assess the internet exposure of each asset, and follow applicable forensic triage procedures. If effective mitigations are unavailable, it may be prudent to remove the vulnerable product from service.

This development highlights the ongoing challenges in securing widely used platforms like Microsoft SharePoint. Organizations must remain vigilant, ensuring timely application of security updates and maintaining robust monitoring practices to detect and respond to potential threats promptly.