VMTech
Discuss a project

Active exploitation targets patched SharePoint authentication bypass

Active exploitation targets patched SharePoint authentication bypass

Threat actors have begun exploiting CVE-2026-55040, a critical Microsoft SharePoint authentication-bypass vulnerability with a CVSS score of 9.1, following the publication of proof-of-concept code by Rapid7. Microsoft patched the issue in its July 2026 Patch Tuesday updates, but telemetry from KEVIntel recorded 12 exploitation attempts since July 19.

Eight of those attempts occurred on August 12 and 13, indicating that public availability of the proof of concept has coincided with increased activity. The observed attempts originated from eight unique IP addresses linked to Hong Kong, Japan, the Netherlands, Taiwan and the United States.

JWT validation flaws enable impersonation

Microsoft describes CVE-2026-55040 as a security-feature bypass caused by weak authentication. Successful exploitation allows an unauthenticated attacker to bypass authentication on a vulnerable SharePoint server and perform arbitrary actions as a SharePoint site user or administrator. Microsoft said an attacker could disclose files and modify data, although the flaw does not affect system availability.

Rapid7 found that the weakness lies in the JWT token parsing and validation logic for Bearer service-to-service tokens. The affected logic is implemented in the SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2 classes.

The exploit chains four issues in the validation pipeline. An attacker can set alg: none in an outer JWT header, avoiding the need for an outer-token signature. The actor token can include SharePoint's own STS certificate thumbprint in its x5t header, resolving a signing key without verification. Rapid7 also found that a resolved certificate outside TrustedSecurityTokenServices can still lead to issuer acceptance, while a non-empty actor-token signature is not verified.

PoC lowers the barrier to attack

Rapid7's Python proof of concept uses a forged JWT to query a target domain controller, enumerate users by SID and locate the SID of a site administrator. That workflow illustrates how an authentication bypass can be turned into access under an impersonated SharePoint identity.

The rise in exploitation follows a broader pattern of attackers adopting public techniques quickly, including ClickFix chains and AI-agent incident activity reporting on ClickFix chains and AI-agent incident activity, as defenders work to validate exposed systems. Defused Cyber said threat actors are using Rapid7's public exploit, but the identities of the operators and their objectives remain unclear.

Patch status is the immediate priority

Organisations running SharePoint should verify that the July 2026 Microsoft security updates are installed across all relevant instances. Because the exploit targets authentication and can operate without prior credentials, teams should treat unpatched servers as a priority for remediation and review their patch status before further exploitation activity develops.

#sharepoint#cybersecurity#vulnerability#patchmanagement
Open analytics
On the site 2 views
min read 3 13.08.2026
Instagram

Active exploitation targets patched SharePoint authentication bypass

Open the post on Instagram ↗