BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

SharePoint CVE-2026-55040 exploited after PoC release

Critical SharePoint vulnerability exploited after PoC release; unauthenticated attackers impersonate users.

  • Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by Rapid7.
  • The flaw allows unauthenticated attackers to bypass authentication, impersonate users, and perform arbitrary operations on vulnerable SharePoint servers.
  • Twelve exploitation attempts have been recorded since July 19, 2026, with a spike on August 12-13, originating from Hong Kong, Japan, the Netherlands, Taiwan, and the U.S.

Threat actors have begun actively exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS score 9.1), following the release of a proof-of-concept code by Rapid7. The critical security feature bypass, which stems from weak authentication, was patched by Microsoft as part of its July 2026 Patch Tuesday updates.

- Advertisement -

“The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said in its advisory. “Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system.”

According to Defused Cyber, threat actors are leveraging the PoC exploit released by Rapid7, indicating fresh flaws are being abused in real-world attacks. Successful exploitation allows an unauthenticated attacker to sidestep authentication on a vulnerable SharePoint server and perform arbitrary operations as a site user or administrator.

The vulnerability, per Rapid7, is due to “several issues” in the JWT token validation pipeline. Specifically, it chains four different weaknesses to allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user. The issue resides in two classes that implement token parsing and validation logic for Bearer service-to-service tokens: SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2.

The exploitation chain involves sending a JWT with “alg: none” in the outer header, using SharePoint’s own STS certificate thumbprint in the x5t header, and providing a non-empty but unverified signature. Rapid7’s Python-based PoC uses the forged JWT token to query a target’s domain controller, enumerate users by SID, and auto-locate the SID for a site administrator.

- Advertisement -

As of writing, it’s unclear who is behind the exploitation activity or what their end goals are. Telemetry data captured by KEVIntel shows that a total of 12 exploitation attempts were recorded since July 19, 2026, with eight taking place on August 12 and 13, indicating the PoC release has played a role in these efforts. The 12 attempts originated from eight unique IP addresses across five countries and regions, including Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. SharePoint users are advised to keep their instances up-to-date for optimal protection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Anthropic tightens AI safety after Claude hacks real systems

Claude accessed real systems after cyber testing environments exposed the models to the internet.Anthropic...

US, CrowdStrike disrupt Sality botnet in $150K crypto theft

US law enforcement and international partners disrupted the Sality botnet, a Malware network active...

21 Global Banks Unite to Launch Dollar Stablecoin by 2027

Twenty-one major banks, including Goldman Sachs, Bank of America, and Citi, are forming a...

StreamRat Android Trojan Hits 570K Meta Users via Fake Ads

Cybersecurity firm ThreatFabric uncovered a new Android banking trojan called StreamRat, spread via fake...

Trump $1 coin enters circulation, on sale today

The U.S. Mint has released a commemorative 2026 $1 coin featuring President Donald Trump,...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading