Threat actors are actively exploiting a newly disclosed vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the release of a proof-of-concept (PoC) code. This critical security flaw, which has a CVSS score of 9.1, allows for an authentication bypass due to weak authentication mechanisms. Microsoft addressed this vulnerability in its July 2026 Patch Tuesday updates.
According to an advisory from Microsoft, the flaw enables impersonation, allowing attackers to disclose files and modify data without affecting system availability. The PoC exploit, released by Rapid7, has been leveraged by threat actors, indicating a trend of rapid abuse of newly discovered vulnerabilities in real-world attacks.
CVE-2026-55040 marks the fifth SharePoint vulnerability exploited this year, following other significant vulnerabilities such as CVE-2026-45659 and CVE-2026-50522. Successful exploitation of this vulnerability allows unauthenticated attackers to bypass authentication on vulnerable SharePoint servers and perform arbitrary operations as site users or administrators.
Rapid7’s analysis indicates that the vulnerability arises from multiple issues in the JWT token validation pipeline, specifically in two classes responsible for parsing and validating Bearer service-to-service (S2S) tokens. Attackers can exploit this vulnerability by sending a specially crafted JWT that bypasses signature verification.
As of now, telemetry data from KEVIntel has recorded 12 exploitation attempts since July 19, 2026, with a notable spike occurring on August 12 and 13, coinciding with the PoC release. These attempts originated from eight unique IP addresses across five countries, including Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. In light of this increased activity, SharePoint users are urged to ensure their systems are updated to mitigate potential risks.
For further details, refer to the full report by The Hacker News.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


