CVE Tools
Back to feed
Exploited in the wild Microsoft SharePoint auth-bypass Microsoft web-app

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Help Net Security·By Sinisa Markovic··1 min read
CVE Tools coverage

Threat actors have begun actively exploiting a critical vulnerability in Microsoft SharePoint, identified as CVE-2026-55040, following the public release of proof-of-concept code by Rapid7. This flaw enables remote unauthenticated attackers to bypass authentication mechanisms by manipulating the JWT token validation process, potentially allowing them to access sensitive files or modify data. While Microsoft had previously issued a fix during its July 2026 Patch Tuesday cycle, recent intelligence indicates that adversaries are now leveraging the available exploits against honeypots and live systems.