Skip to content
feed: live
>_ 0dayNews
microsoft
● Breaking

SharePoint CVE-2026-55040 Exploited After PoC Drop

Rapid7's 30-day embargo on CVE-2026-55040 has expired. A public PoC is circulating and active exploitation is confirmed. The July 2026 CU patches it. Apply it now.

SharePoint CVE-2026-55040 Exploited After PoC Drop
Photo: Mussklprozz / Wikimedia Commons · CC BY-SA 3.0
airgap airgap · Published · 2 min read

Active exploitation confirmed. A public proof-of-concept for CVE-2026-55040 is circulating. Threat actors moved on it fast.

The vulnerability. CVE-2026-55040 is a critical (CVSS 9.1) authentication bypass in Microsoft SharePoint Server. Unauthenticated attackers can exploit failures in the JWT token validation pipeline to assume an arbitrary user identity over the network — no credentials required. On-prem SharePoint Server only; SharePoint Online is handled by Microsoft on the tenant side.

Why it’s being exploited now. Rapid7 disclosed the bug on July 14 under a coordinated embargo — withholding full technical detail for roughly 30 days to give defenders a patching window. That window has closed. Technical details are public. A PoC followed. Active exploitation followed the PoC.

This is the expected sequence. The embargo bought time. For the orgs that didn’t use it, time is up.

Timeline (confirmed):

  • 2026-07-14 — Rapid7 discloses CVE-2026-55040; Microsoft ships fix in July Patch Tuesday CU
  • 2026-07-14 — CISA flags exploitation risk
  • 2026-08-13 — Rapid7 embargo expires; full technical detail goes public
  • 2026-08-13 — Active exploitation observed in the wild after PoC circulates

(The Hacker News, SecurityWeek)

One important note about scope. Rapid7’s research chained CVE-2026-55040 with a separate SharePoint RCE vulnerability to reach unauthenticated remote code execution end-to-end. As we reported in July, the RCE half was disclosed to Microsoft but had not yet been patched. Whether attackers are currently chaining the full RCE sequence or using CVE-2026-55040 alone for initial access is unconfirmed — treat the full pre-auth RCE scenario as the risk model until Rapid7 or Microsoft states otherwise.

What to do.

The July 2026 cumulative update fixes this. That’s it. Apply it.

  1. If you haven’t applied the July 2026 SharePoint Server CU: stop reading, patch now. You are exposed to confirmed active exploitation.
  2. If you applied July but not August CU: Apply August as well — August Patch Tuesday landed this week with 400+ fixes and your SharePoint maintenance window is already open.
  3. Review SharePoint access logs. Look for anomalous JWT-based authentication activity since mid-July. A CVSS 9.1 auth bypass gives attackers a valid session — they won’t necessarily trigger obvious alerts immediately.
  4. If you cannot patch today: Isolate on-prem SharePoint from untrusted network segments. Documented CISA guidance applies. This is a temporary control, not a substitute.

SharePoint Online users: nothing to do here. Microsoft manages tenant-side patching.


This is the second SharePoint CVE to hit active exploitation in the last month. CVE-2026-45659 was confirmed in ransomware campaigns last week. Both are patched in the same July CU. If your SharePoint Server estate is fully patched through July, you’re covered on both. If not — both are being used against unpatched targets now.

Sources: The Hacker News, SecurityWeek, MSRC advisory, Rapid7 disclosure.

Related CVEs

Found this useful? Share it.