// Microsoft AzureCRITICAL
Microsoft SharePoint authentication bypass CVE-2026-55040 is under active exploitation following Rapid7's public disclosure on August 12, 2026. The JWT token validation flaw allows attackers to impersonate SharePoint users without privileges. Weaponized exploit code is already in use against honeypots. When chained with CVE-2026-63520 (SharePoint RCE), the vulnerabilities enable unauthenticated remote code execution. Microsoft patched CVE-2026-55040 in July 2026; administrators should verify patching on SharePoint Enterprise Server 2016 and Server 2019 deployments.
- Hackers leverage new Microsoft SharePoint exploit in attacks(opens in a new tab)
- Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Exe(opens in a new tab)
- Attackers Exploit SharePoint Authentication Bypass After Public (opens in a new tab)
- Hackers Actively Exploiting Microsoft SharePoint Vulnerability F(opens in a new tab)
- SharePoint CVE-2026-55040 Actively Exploited: Attackers Forge Ad(opens in a new tab)
- CISA Adds Microsoft SharePoint Weak Authentication Vulnerability(opens in a new tab)
// Get alerts for Microsoft Azure