
A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability released on Tuesday by cybersecurity firm Rapid7 is already being used in attacks.
Tracked as CVE-2026-55040This authentication bypass vulnerability in the JWT token validation pipeline could be exploited by attackers who do not have permissions to perform operations as a SharePoint site user or administrator.
Microsoft fixed the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
“The authentication function could be bypassed as this vulnerability allows impersonation.” it said. “Exploitation of this vulnerability could allow an attacker to expose files and modify data, but the attacker cannot affect the availability of the system.”
A detailed technical description to CVE-2026-55040 was published on Tuesday by Rapid7 security researcher Stephen Fewer along with a PoC exploit.
The threat intelligence company Defused reported this today Rapid7’s exploit code has already been used as a weapon in attacks on its honeypots.
“Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots,” Defused warned. “The vulnerability is a Microsoft SharePoint JWT authentication bypass, for which Rapid7 published a technical description and proof-of-concept code yesterday.”
Internet threat monitor Shadowserver is currently tracking over 8,500 Microsoft SharePoint servers exposed online. However, there is no information about how many of these are honeypots or have already been patched against this vulnerability.

Although Microsoft has described this vulnerability as an attractive target for attackers, it has so far reported it to have been successfully exploited.
Likely based on Microsoft’s exploitability assessment, the US Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to protect their SharePoint servers from potential CVE-2026-55040 attacks.
CISA urged security teams to avoid directly exposing SharePoint servers to the Internet unless absolutely necessary and to review the official Microsoft SharePoint Server security hardening guidelines.
It was also recommended to block external access to SharePoint Central Administration and limit farm and database communications to required systems. If an Internet presence is required, CISA recommends placing servers behind a Layer 7 reverse proxy or similar application-level security control.
The cybersecurity agency has been warning since November 2021 14 actively exploited Microsoft SharePoint vulnerabilitiesEight of these were also exploited in ransomware attacks.
On Tuesday, CISA also confirmed that a high-level remote code execution vulnerability in Microsoft SharePoint (CVE-2026-45659), which has been actively exploited since early July, is now being exploited by ransomware gangs.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.


