Exploits

Microsoft SharePoint CVE-2026-55040 Exploitation Underway

Published  ·  5 min read

Microsoft SharePoint CVE-2026-55040 Exploitation

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability. The exploit came after the publication of proof-of-concept code by Rapid7.

This particular vulnerability has the ID CVE-2026-55040 and CVSS score of 9.1. It is an example of critical security feature bypassing vulnerability and appears due to the weak authentication. The flaw was patched by Microsoft in July 2026 Patch Tuesday Updates.

Let me break down the Microsoft SharePoint CVE-2026-55040 exploitation campaign and what administrators need to know.

Key Points About the Vulnerability

  • CVE-2026-55040 is a SharePoint authentication bypass
  • CVSS score: 9.1 (Critical)
  • Patched in Microsoft's July 2026 Patch Tuesday
  • Unauthenticated attackers can impersonate site users
  • Attackers can disclose files and modify data
  • Availability is not impacted
  • Rapid7 released a PoC exploit
  • Active exploitation has been observed

How the Vulnerability Works

The Microsoft SharePoint CVE-2026-55040 exploitation is due to "several issues" in the JWT token validation pipeline. The vulnerability resides in two classes:

  • SPJsonWebSecurityTokenHandlerV2
  • SPJsonWebSecurityBaseTokenHandlerV2

The Exploit Chain:

Step 1: Token Forgery

  • Attacker sends a JWT with alg: none in the outer header
  • No signature is required in the outer token

Step 2: Certificate Resolution

  • The actor token's x5t header contains SharePoint's own STS certificate thumbprint
  • This makes it possible to resolve a signing key with no verification

Step 3: Issuer Acceptance

  • The resolved certificate is not in TrustedSecurityTokenServices
  • This allows the issuer to be accepted

Step 4: Signature Bypass

  • The actor token's signature is a non-empty value (e.g., AAAA)
  • The signature is never verified

Step 5: Impersonation

  • Attacker forges a valid JWT
  • Can impersonate any SharePoint site user

What the Attacker Can Do

The Microsoft SharePoint CVE-2026-55040 exploitation allows attackers to:

  • Bypass authentication on a vulnerable SharePoint server
  • Perform arbitrary operations as a SharePoint site user
  • Perform arbitrary operations as a SharePoint site administrator
  • Disclose files
  • Modify data

Rapid7's PoC Capabilities:

  • Queries a target's domain controller
  • Enumerates users by SID
  • Auto-locates the SID for the user
  • Finds a site administrator

Exploitation Activity

The Microsoft SharePoint CVE-2026-55040 exploitation is being actively pursued by attackers:

Exploitation Timeline:

  • July 2026: Microsoft patches the vulnerability
  • August 2026: Rapid7 releases PoC exploit
  • Since July 19: 12 exploitation attempts recorded

Recent Activity:

  • August 12-13: 8 exploitation attempts
  • This indicates PoC release has played a role

Attacker Origins:

  • 8 unique IP addresses
  • 5 countries and regions:
    • Hong Kong
    • Japan
    • Netherlands
    • Taiwan
    • United States

The Fifth SharePoint Vulnerability of 2026

The Microsoft SharePoint CVE-2026-55040 exploitation is the fifth SharePoint vulnerability to be exploited this year:

  • CVE-2026-45659
  • CVE-2026-56164
  • CVE-2026-58644
  • CVE-2026-50522
  • CVE-2026-55040

This pattern indicates that SharePoint is a continued target for attackers. Security should be the first concern of organizations regarding SharePoint.

The Rapid7 PoC

Rapid7 published a Python-based PoC for CVE-2026-55040:

PoC Capabilities:

  • Uses the forged JWT token
  • Queries a target's domain controller
  • Enumerates users by SID
  • Auto-locates the SID for a site administrator

The Role of the PoC:

  • The PoC release has accelerated exploitation
  • Eight of 12 attempts occurred after PoC release
  • Threat actors are quickly weaponizing new flaws

What Organizations Should Do

The Microsoft SharePoint CVE-2026-55040 exploitation requires immediate action:

Immediate Steps:

  • Apply Microsoft's July 2026 Patch Tuesday updates
  • Prioritize CVE-2026-55040
  • Check for unpatched SharePoint instances

Detection:

  • Monitor for unusual JWT tokens
  • Look for alg: none in JWT headers
  • Check for authentication bypass attempts
  • Review SharePoint logs for unauthorized access

Additional Measures:

  • Audit SharePoint user permissions
  • Review site administrator accounts
  • Monitor for unusual file access
  • Implement additional authentication controls

Microsoft's Advisory

Microsoft's advisory for CVE-2026-55040 stated:

  • "The authentication feature could be bypassed as this vulnerability allows impersonation"
  • "Exploiting this vulnerability could allow an attacker to disclose files and modify data"
  • "The attacker cannot impact the availability of the system"

Wrapping It Up

The Microsoft SharePoint CVE-2026-55040 exploitation is a critical threat to organizations using SharePoint. The vulnerability allows unauthenticated attackers to impersonate site administrators.

Key considerations to remember:

  • CVE-2026-55040 is a critical vulnerability related to the bypassing of authentication
  • CVSS Score: 9.1
  • Vulnerability Patched: July 2026
  • PoC exploit developed by Rapid7
  • Exploitation incidents have been observed
  • It is the fifth such vulnerability exploited this year

Organizations are urged to install patches provided by Microsoft in its July 2026 Patch Tuesday update. Beware of any suspicious tokens or any authentication bypass attacks. Also, check the SharePoint administrator's credentials.

Leveraging the SharePoint Microsoft CVE-2026-55040 vulnerability is yet another example of how quickly the malicious actors  move to exploit any vulnerability.

FAQ Section

What is CVE-2026-55040?

It is a critical SharePoint authentication bypass vulnerability. It allows unauthenticated attackers to impersonate site users and administrators. The CVSS score is 9.1.

How does the vulnerability work?

The vulnerability chains four weaknesses in JWT token validation. Attackers can forge a valid JWT and impersonate any SharePoint site user.

Is the vulnerability being exploited?

Yes. Rapid7 released a PoC exploit, and active exploitation has been observed. Eight of 12 exploitation attempts occurred after the PoC release.

Which countries are the attacks originating from?

Attacks have originated from Hong Kong, Japan, the Netherlands, Taiwan, and the United States.

What Should SharePoint Administrators Do?

Install Microsoft July 2026 Patch Tuesday update right away. Watch out for any suspicious JWT tokens and authentication bypass attempts. Inspect SharePoint administrators.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067