BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

SharePoint CVE-2026-55040 exploited after PoC release

Critical SharePoint vulnerability exploited after PoC release; unauthenticated attackers impersonate users.

  • Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by Rapid7.
  • The flaw allows unauthenticated attackers to bypass authentication, impersonate users, and perform arbitrary operations on vulnerable SharePoint servers.
  • Twelve exploitation attempts have been recorded since July 19, 2026, with a spike on August 12-13, originating from Hong Kong, Japan, the Netherlands, Taiwan, and the U.S.

Threat actors have begun actively exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS score 9.1), following the release of a proof-of-concept code by Rapid7. The critical security feature bypass, which stems from weak authentication, was patched by Microsoft as part of its July 2026 Patch Tuesday updates.

- Advertisement -

“The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said in its advisory. “Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system.”

According to Defused Cyber, threat actors are leveraging the PoC exploit released by Rapid7, indicating fresh flaws are being abused in real-world attacks. Successful exploitation allows an unauthenticated attacker to sidestep authentication on a vulnerable SharePoint server and perform arbitrary operations as a site user or administrator.

The vulnerability, per Rapid7, is due to “several issues” in the JWT token validation pipeline. Specifically, it chains four different weaknesses to allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user. The issue resides in two classes that implement token parsing and validation logic for Bearer service-to-service tokens: SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2.

The exploitation chain involves sending a JWT with “alg: none” in the outer header, using SharePoint’s own STS certificate thumbprint in the x5t header, and providing a non-empty but unverified signature. Rapid7’s Python-based PoC uses the forged JWT token to query a target’s domain controller, enumerate users by SID, and auto-locate the SID for a site administrator.

- Advertisement -

As of writing, it’s unclear who is behind the exploitation activity or what their end goals are. Telemetry data captured by KEVIntel shows that a total of 12 exploitation attempts were recorded since July 19, 2026, with eight taking place on August 12 and 13, indicating the PoC release has played a role in these efforts. The 12 attempts originated from eight unique IP addresses across five countries and regions, including Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. SharePoint users are advised to keep their instances up-to-date for optimal protection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Claude AI discovers unknown enzyme system in viruses

Anthropic's AI model Claude spent 21 hours and roughly 210 million tokens searching DNA...

AI CEOs Urge UN Cooperation on Catastrophic Risks

OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei urged the UN Security Council...

HTX PoR errors: $0 USDS, wrong USDD claims

HTX's September proof of reserves overstated USDS holdings by 360,949.90 tokens — the address...

Former Hack VC partner Hsin-Ju Chuang dies at 37

Hsin-Ju Chuang, a former partner at Hack VC and founder of Dystopia Labs, died...

MikroTik SSH flaws chained for full router takeover

A chain of two SSH vulnerabilities—CVE-2026-67279 and CVE-2026-86060—allows unauthenticated attackers to gain full administrative...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading