CVE Tools
Back to feed
Exploited in the wild Microsoft web-app auth-bypass

Hackers leverage new Microsoft SharePoint exploit in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Cybercriminals have begun deploying a proof-of-concept exploit for the critical authentication bypass flaw tracked as CVE-2026-55040, which affects Microsoft SharePoint Server. Published by Rapid7, the code allows unauthorized users to impersonate valid identities within SharePoint environments by exploiting weaknesses in the JWT token validation process. Although Microsoft patched this vulnerability during the July 2026 Patch Tuesday cycle for SharePoint Enterprise Server 2016 and SharePoint Server 2019, threat intelligence firm Defused confirmed that attackers are actively using the tool against exposed systems.