Microsoft SharePoint CVE-2026-55040 Exploit Is Already Being Used in Attacks
A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability is already being used in attacks, according to cybersecurity firm Rapid7 and threat intelligence company Defused.
Tracked as CVE-2026-55040, the authentication bypass vulnerability affects SharePoint’s JSON Web Token (JWT) validation pipeline. An unauthenticated attacker could exploit the flaw to perform operations as a SharePoint site user or administrator without the required permissions.
Microsoft addressed CVE-2026-55040 in its July 2026 Patch Tuesday security updates and urged customers to install the patches on systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
Microsoft described the vulnerability as a spoofing flaw that could allow an attacker to bypass authentication. The company said that successful exploitation could allow attackers to disclose files and modify data, although they would not be able to disrupt system availability.
Rapid7 security researcher Stephen Fewer published detailed technical analysis of CVE-2026-55040 on Tuesday, along with a publicly available proof-of-concept exploit.
On Wednesday, threat intelligence firm Defused reported that Rapid7’s exploit code had already been weaponized in an attack against its honeypot infrastructure.
“The attacker is currently using the @rapid7 PoC for CVE-2026-55040 against our SharePoint honeypot,” Defused warned. “This vulnerability is a Microsoft SharePoint JWT authentication bypass for which Rapid7 published technical documentation and proof-of-concept code yesterday.”
Internet threat monitoring organization Shadowserver is currently tracking more than 8,500 Microsoft SharePoint servers exposed to the internet. It is not yet known how many of these systems are honeypots or how many have been updated to address CVE-2026-55040.

Microsoft currently classifies CVE-2026-55040 as an attractive target for attackers, although the company has not yet marked the vulnerability as exploited in the wild.
Based on Microsoft’s exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to protect Microsoft SharePoint servers from potential CVE-2026-55040 attacks.
CISA advised organizations not to expose SharePoint servers directly to the internet unless required. Security teams should also review Microsoft’s official SharePoint Server security hardening guidance and ensure that all available security updates have been installed.
Organizations should block external access to SharePoint Central Administration and restrict farm and database communications to only the systems that require access. When internet exposure is necessary, CISA recommends placing SharePoint behind a Layer 7 reverse proxy or another application-layer security control.
Since November 2021, CISA has added 14 Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog. Eight of those flaws have also been exploited in ransomware attacks.
CISA also confirmed on Tuesday that a high-severity Microsoft SharePoint remote code execution vulnerability, tracked as CVE-2026-45659, is now being exploited by ransomware groups. The vulnerability was first reported as actively exploited in early July.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




