Exploited in the wild Microsoft SharePoint auth-bypass Microsoft web-app
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
CVE Tools coverage
Threat actors have begun actively exploiting a critical vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the public release of proof-of-concept code by Rapid7. This flaw enables remote unauthenticated attackers to bypass authentication mechanisms by manipulating the JWT token validation process, potentially allowing them to access sensitive files or modify data. While Microsoft had previously issued a fix during its July 2026 Patch Tuesday cycle, recent intelligence indicates that adversaries are now leveraging the available exploits against honeypots and live systems.