Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers leverage new Microsoft SharePoint exploit in attacks
Rapid7 published a proof-of-concept exploit for CVE-2026-55040, a critical Microsoft SharePoint authentication bypass, and it is already being used in attacks against SharePoint honeypots. Microsoft and CISA have urged defenders to harden and restrict exposed SharePoint servers while noting that CVE-2026-45659 is also being abused by ransomware gangs. #Rapid7 #CVE-2026-55040 #MicrosoftSharePoint #CISA #CVE-2026-45659

Keypoints

  • Rapid7 released a PoC exploit for CVE-2026-55040.
  • The flaw bypasses SharePoint JWT authentication and enables impersonation.
  • Defused said the PoC is already being weaponized against honeypots.
  • Microsoft patched the issue in July 2026 Patch Tuesday for SharePoint 2016 and 2019.
  • CISA advised limiting Internet exposure and hardening SharePoint deployments.

Read More: https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/