bleeping-computer · Crawled Aug 12, 2026

Hackers leverage new Microsoft SharePoint exploit in attacks

Read original article ↗

AI Summary

Attackers are actively exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint's JWT token validation pipeline, to perform unauthorized actions as SharePoint users or administrators. A proof-of-concept exploit was published by Rapid7 and has already been weaponized, with attacks observed targeting SharePoint honeypots. Microsoft patched the vulnerability in its July 2026 updates, but over 8,500 SharePoint servers remain exposed online. CISA has issued warnings urging organizations to secure internet-facing SharePoint servers and apply security hardening measures.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.