CVE Tools
Back to feed
Exploited in the wild Microsoft SharePoint auth-bypass Microsoft rce

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Microsoft is actively addressing CVE-2026-55040, a critical authentication bypass in SharePoint that allows unauthenticated attackers to forge JWTs and impersonate administrators or site users. Following the release of a public proof-of-concept by Rapid7 this week, threat actors have begun exploiting the vulnerability, which was patched in Microsoft's July 2026 Patch Tuesday update. With a CVSS score of 9.1, the flaw stems from weak token validation logic that enables file disclosure and data modification without affecting system availability. Administrators should immediately apply the latest updates to prevent unauthorized access.