a researcher posted SharePoint exploit code on Tuesday. attackers were forging admin access by Thursday

Microsoft patched this JWT flaw back in July. A public proof-of-concept turned it into real attacks in under 48 hours — here's exactly what's broken…

Aliteq
Priya Nair · Software & Systems Editor

CVE-2026-55040 is a CVSS 9.1 authentication bypass in the JWT validation pipeline of on-premises SharePoint Server.

It lets an unauthenticated attacker forge a valid JWT and impersonate any user they can identify by Active Directory SID or UPN — no password needed.

Microsoft patched it on July 14, 2026. Rapid7's public proof-of-concept went live August 11, and exploitation attempts spiked within 48 hours.

Affected: SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition — on-premises installs only.

Shadowserver was still tracking over 8,500 exposed SharePoint servers on the open internet as of the PoC's release.

My read

The gap between 'researcher publishes technical writeup' and 'attackers are actively exploiting it' keeps shrinking in 2026 — SAP's Commerce Cloud bug fell in 72 hours flat, and this one wasn't much…

Aliteq

Read the full story

a researcher posted SharePoint exploit code on Tuesday. attackers were forging admin access by Thursday

Read the full story on Aliteq