A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks.
Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
“The authentication feature could be bypassed as this vulnerability allows impersonation,” it said. “Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system.”
A detailed technical write-up on CVE-2026-55040 was published by Rapid7 security researcher Stephen Fewer on Tuesday, together with a PoC exploit.
Earlier today, threat intelligence company Defused reported that Rapid7’s exploit code has already been weaponized in attacks targeting its honeypots.
“Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots,” Defused warned. “The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday.”
Internet threat watchdog Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online. However, there is no information on how many of them are honeypots or have already been patched against this security flaw.
While Microsoft has labeled this security flaw as an attractive target for attackers, it has yet flag it as successfully exploited in the wild.
Likely based on Microsoft’s exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.
CISA urged security teams to avoid directly exposing SharePoint servers on the Internet unless necessary and to review Microsoft’s official SharePoint Server security-hardening guidance.
It also recommended blocking external access to SharePoint Central Administration and restricting farm and database communication to the required systems. Where Internet exposure is required, CISA recommends placing servers behind a Layer 7 reverse proxy or similar application-layer security control.
Since November 2021, the cybersecurity agency has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, with eight of them also exploited in ransomware attacks.
On Tuesday, CISA also confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Critical SharePoint RCE flaw exploited to steal machine keys
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
N-able warns of N-central auth bypass flaw exploited in attacks
vBulletin fixes critical pre-auth RCE flaw with public exploit
Check Point warns of SmartConsole zero-day exploited in attacks
LexisNexis shuts down services after suspicious activity on servers
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Valve notifies Steam hardware customers of a data breach
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.
Overdue a password health-check? Audit your Active Directory for free
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



