Active Exploitation of Microsoft SharePoint JWT Token Bypass Vulnerability

Active Exploitation of Microsoft SharePoint JWT Token Bypass Vulnerability

First seen 12 Aug 2026, 20:04 UTC Rapid7Petri 85% similarity 74.0

Article Content

Browse articles
ThreatCluster

On July 14, 2026, CVE-2026-55040 was disclosed, revealing a critical authentication bypass vulnerability in Microsoft SharePoint's JWT token validation process. The flaw allows remote unauthenticated attackers to forge valid JWTs, impersonating SharePoint users and potentially gaining administrative access. Following the release of a public proof-of-concept exploit on July 28, attacks against exposed SharePoint servers have surged, as confirmed by threat intelligence firm Defused. Organizations are urged to prioritize patching affected SharePoint servers and review logs for unusual activity. The vulnerability affects SharePoint Server Subscription Edition version 16.0.19725.20210 and is considered a high-priority security issue.

Key Points: • CVE-2026-55040 allows unauthenticated remote attackers to bypass SharePoint authentication. • Public exploit code has led to active attacks against vulnerable SharePoint servers. • Organizations must patch affected systems and monitor for unauthorized access.

ThreatCluster AI How this analysis works

Timeline

2026-07-14
CVE-2026-55040 published
Microsoft and Rapid7 disclosed a critical authentication bypass vulnerability in SharePoint.
Rapid7
2026-07-28
Public PoC exploit released
A proof-of-concept exploit was made public, enabling easier exploitation of the vulnerability.
Rapid7
2026-08-12
Active attacks reported
Threat intelligence firm Defused confirmed attackers are exploiting the vulnerability against SharePoint honeypots.
Petri

Community

Browse all →

Tracked Entities in This Story