What happened
Attackers are actively exploiting CVE-2026-55040, a critical authentication bypass in on-premises Microsoft SharePoint Server, following Rapid7's publication of a technical analysis and working proof-of-concept exploit on August 11. The flaw, rated 9.1 on the CVSS scale, chains four separate weaknesses in SharePoint's JSON Web Token validation pipeline. The result: a remote attacker with no credentials can forge a valid token and impersonate any SharePoint user, including administrators. Telemetry cited by The Hacker News recorded 12 exploitation attempts since July 19, with eight of them landing on August 12 and 13 from eight IP addresses across five countries. Microsoft patched the bug in its July 2026 Patch Tuesday release, but researchers estimate thousands of on-premises SharePoint servers remain reachable from the internet, and reporting indicates the bypass can be chained with a second, still-unpatched bug to reach full remote code execution.
Why it matters for your business
Plenty of small firms and government contractors in the DMV still run SharePoint on their own servers for file shares and intranets, often installed years ago and rarely updated. This bug requires no password, no phishing, and no user mistake, and it hands an attacker the same view of your documents that your administrator has. The month between the patch and the public exploit is exactly the window attackers count on.
What to do about it
If you run SharePoint Server 2016, 2019, or Subscription Edition on-premises, confirm the July 2026 security updates are installed today. Then take two more steps:
- Remove SharePoint from direct internet exposure; put it behind a VPN or identity-aware proxy.
- Review sign-in and audit logs back to mid-July for sessions or file access you cannot explain.
If you use SharePoint Online through Microsoft 365, this vulnerability does not apply to you.
