BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

SharePoint CVE-2026-55040 exploited after PoC release

Critical SharePoint vulnerability exploited after PoC release; unauthenticated attackers impersonate users.

  • Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by Rapid7.
  • The flaw allows unauthenticated attackers to bypass authentication, impersonate users, and perform arbitrary operations on vulnerable SharePoint servers.
  • Twelve exploitation attempts have been recorded since July 19, 2026, with a spike on August 12-13, originating from Hong Kong, Japan, the Netherlands, Taiwan, and the U.S.

Threat actors have begun actively exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS score 9.1), following the release of a proof-of-concept code by Rapid7. The critical security feature bypass, which stems from weak authentication, was patched by Microsoft as part of its July 2026 Patch Tuesday updates.

- Advertisement -

“The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said in its advisory. “Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system.”

According to Defused Cyber, threat actors are leveraging the PoC exploit released by Rapid7, indicating fresh flaws are being abused in real-world attacks. Successful exploitation allows an unauthenticated attacker to sidestep authentication on a vulnerable SharePoint server and perform arbitrary operations as a site user or administrator.

The vulnerability, per Rapid7, is due to “several issues” in the JWT token validation pipeline. Specifically, it chains four different weaknesses to allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user. The issue resides in two classes that implement token parsing and validation logic for Bearer service-to-service tokens: SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2.

The exploitation chain involves sending a JWT with “alg: none” in the outer header, using SharePoint’s own STS certificate thumbprint in the x5t header, and providing a non-empty but unverified signature. Rapid7’s Python-based PoC uses the forged JWT token to query a target’s domain controller, enumerate users by SID, and auto-locate the SID for a site administrator.

- Advertisement -

As of writing, it’s unclear who is behind the exploitation activity or what their end goals are. Telemetry data captured by KEVIntel shows that a total of 12 exploitation attempts were recorded since July 19, 2026, with eight taking place on August 12 and 13, indicating the PoC release has played a role in these efforts. The 12 attempts originated from eight unique IP addresses across five countries and regions, including Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. SharePoint users are advised to keep their instances up-to-date for optimal protection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bernstein Hikes Microsoft Target to $660, Bullish on AI

Bernstein raised its Microsoft (MSFT) price target from $647 to $660, maintaining an outperform...

Bitwise: Crypto valuations could double on buybacks, burns

Bitwise CIO Matt Hougan argues crypto valuations could at least double as protocols route...

ASX shareholder seeks court approval to sue directors over blockchain failure

A shareholder is seeking court permission to sue former ASX officers and directors over...

AI pattern breaks Flock, Clearview, Axon cameras at Def Con

Bill Swearingen’s noRecognition project generates patterns that stop camera software from classifying what it...

Cerebras shares sink 15% as hardware revenue drops 23% in Q2

Cerebras Systems stock fell 15% after-hours despite raising its full-year outlook, as hardware revenue...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Top 3 Bitcoin Casinos - Quick Comparison ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading