Defenders running unpatched SharePoint servers face an active exploitation wave tied to CVE-2026-55040 (CVSS 9.1), an authentication bypass Microsoft fixed in July. Attackers are now using the proof-of-concept code Rapid7 shipped this week, according to telemetry from threat intel firm KEVIntel and honeypot operator Defused.
The flaw lives in the JWT token validation pipeline. Rapid7’s Stephen Fewer showed how four weaknesses combine so a remote attacker can forge a valid token and act as any site user, including an administrator. The forged token needs no real signature, and SharePoint’s own certificate thumbprint is borrowed to satisfy key resolution.
Twelve exploitation attempts have been logged since July 19, eight of them on August 12 and 13 once the PoC went public. The activity traces to eight IP addresses in Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. Microsoft warns the bug lets attackers read files and alter data, though not take systems offline.
Pairing the bypass with CVE-2026-63520 could produce unauthenticated remote code execution, NHS England Digital warned. CISA’s advice is to harden SharePoint, keep instances patched, and avoid direct internet exposure. With working exploit code circulating, unpatched servers should be treated as compromised.
