Threat actors are actively exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication bypass, after Rapid7 released proof-of-concept code. The attacks use forged JWT tokens to impersonate users and administrators, with telemetry showing 12 exploitation attempts across multiple countries and regions. #CVE-2026-55040 #MicrosoftSharePoint #Rapid7
Keypoints
- Attackers are exploiting CVE-2026-55040 soon after a PoC was published.
- The flaw is a critical SharePoint authentication bypass caused by weak token validation.
- Exploitation can let an unauthenticated attacker impersonate a SharePoint user or administrator.
- The attack chains multiple JWT validation weaknesses in SharePoint token handlers.
- Telemetry recorded 12 exploitation attempts from eight IPs across five countries and regions.
Read More: https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html