// Alert

Microsoft 365 threat report

Microsoft SharePoint Server on-premises vulnerability CVE-2026-55040 allows unauthenticated attackers to bypass authentication via forged JSON Web Tokens. The flaw, affecting SharePoint Server Subscription Edition, 2019, and 2016, was confirmed in active exploitation and added to CISA's Known Exploited Vulnerabilities catalog on August 18, 2026. Microsoft issued fixes in July 2026; organizations delaying patching face immediate risk from proof-of-concept exploits now in the wild.

// Get alerts for Microsoft 365