hacker-news · Crawled Aug 13, 2026

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

8 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS score: 9.1), following the public release of a proof-of-concept (PoC) exploit by Rapid7. The flaw allows unauthenticated attackers to forge JWT tokens and impersonate SharePoint users by exploiting weaknesses in the JWT validation pipeline, specifically within SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2 classes. Exploitation enables unauthorized access to files and data modification on vulnerable servers. Telemetry shows a spike in exploitation attempts originating from multiple countries, with 12 observed attempts as of mid-August 2026, eight of which occurred immediately after the PoC release.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
IP 8[.]39[.]217[.]15 Details →
IP 103[.]173[.]174[.]138 Details →
IP 116[.]203[.]144[.]105 Details →
IP 139[.]177[.]188[.]146 Details →
IP 147[.]185[.]221[.]178 Details →
IP 185[.]183[.]128[.]194 Details →
IP 193[.]243[.]178[.]226 Details →
IP 207[.]180[.]221[.]146 Details →