A proof-of-concept exploit for a critical Microsoft SharePoint vulnerability is already being used in attacks, only a day after Rapid7 published technical details and exploit code. The flaw allows unauthenticated attackers to impersonate SharePoint users or administrators and access or modify data.
Exploit code targets SharePoint authentication bypass
The vulnerability, tracked as CVE-2026-55040, affects the JWT token-validation process in Microsoft SharePoint. Attackers do not need valid credentials to exploit the SharePoint JWT flaw.
Successful exploitation allows an attacker to perform actions as a SharePoint site user or administrator. Microsoft says this could expose files and allow data modification, although it does not affect system availability.
Microsoft fixed the issue in its July 2026 Patch Tuesday updates. The company urged organisations running SharePoint Enterprise Server 2016 and SharePoint Server 2019 to install the available security updates.
Rapid7 researcher Stephen Fewer published a detailed technical analysis and proof-of-concept code on Tuesday. Threat-intelligence company Defused reported the following day that attackers had already used the public exploit against its SharePoint honeypots.
Thousands of SharePoint servers remain exposed
Shadowserver tracks more than 8,500 Microsoft SharePoint servers exposed to the internet. It is unclear how many of those servers are honeypots, have been patched or remain vulnerable to the SharePoint JWT flaw.
Microsoft has classified CVE-2026-55040 as an attractive target for attackers. However, the company has not yet listed the vulnerability as actively exploited in the wild.
The speed at which the exploit code appeared in attacks highlights the risk for organisations that have not applied July’s updates. Public-facing SharePoint servers may be particularly attractive targets because attackers can test exposed systems remotely.
CISA urges organisations to restrict access
CISA warned network defenders about potential CVE-2026-55040 attacks on July 15. The agency advised organisations not to expose SharePoint servers directly to the internet unless it is necessary.
Where public access is required, CISA recommends placing the server behind a Layer 7 reverse proxy or another application-layer security control.
Organisations should also block external access to SharePoint Central Administration. In addition, they should restrict communication between SharePoint farm servers and databases to only the systems that require it.
Security teams should review Microsoft’s SharePoint hardening guidance, apply the July 2026 security updates and investigate unusual authentication activity. Monitoring for unexpected account impersonation or changes to SharePoint content may help identify attempted exploitation.
SharePoint remains a frequent attack target
CISA has added 14 actively exploited Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021. Eight of those flaws were also used in ransomware attacks.
On Tuesday, CISA also confirmed that ransomware groups are exploiting CVE-2026-45659, a high-severity SharePoint remote-code-execution vulnerability that has been under active attack since early July.
The latest activity shows why organisations should treat the SharePoint JWT flaw as urgent. Applying the patch and reducing unnecessary internet exposure remain the most important steps for limiting the risk.


0 responses to “Hackers exploit new Microsoft SharePoint JWT flaw in attacks”