// Microsoft 365CRITICAL
Microsoft SharePoint Server on-premises vulnerability CVE-2026-55040 allows unauthenticated attackers to bypass authentication via forged JSON Web Tokens. The flaw, affecting SharePoint Server Subscription Edition, 2019, and 2016, was confirmed in active exploitation and added to CISA's Known Exploited Vulnerabilities catalog on August 18, 2026. Microsoft issued fixes in July 2026; organizations delaying patching face immediate risk from proof-of-concept exploits now in the wild.
// Get alerts for Microsoft 365