Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.