TechNewsReel
Live

Attackers Exploit Critical SharePoint Authentication Bypass After PoC Release

A critical flaw in Microsoft SharePoint allows unauthenticated attackers to impersonate administrators, prompting urgent patching after active exploitation emerged in August.

TechNewsReel Newsroom · August 13, 2026

Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, designated as CVE-2026-55040. The flaw allows unauthenticated remote attackers to impersonate any site user, including those with administrative privileges, following the release of public proof-of-concept (PoC) code.

The vulnerability carries a CVSS score of 9.1 and is categorized under CWE-1390 for weak authentication. Technical analysis from Rapid7 reveals the flaw originates in the JSON Web Token (JWT) validation pipeline. By exploiting this weakness, an attacker can assume the identity of a target user if they possess that user's Active Directory (AD) Security ID (SID) or User Principal Name (UPN).

Discovery and Patching

Rapid7 Labs discovered the vulnerability during a research project for the Pwn2Own Berlin 2026 competition. The discovery process was notable for its methodology; researchers utilized an agentic AI workflow over 24 active days to uncover the exploit chain.

Microsoft addressed the issue in July 2026 as part of its Patch Tuesday updates. Patches were released for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Despite the availability of these fixes, active exploitation began to surface in August 2026 as the public PoC code became available to a wider range of threat actors.

Industry Implications

Because SharePoint serves as a central hub for corporate intranets and the storage of sensitive enterprise data, the impact of this vulnerability is severe. The ability for an unauthenticated external actor to gain administrative control provides a high-impact entry point for data theft or deeper network penetration.

Rapid7 Labs noted that CVE-2026-55040 can be chained to additional vulnerabilities within the authenticated attack surface of a target site. Once an attacker bypasses authentication, they can leverage their impersonated administrative status to execute further attacks that would otherwise be blocked by security permissions.

What to Watch

Organizations that have not yet applied the July 2026 updates remain highly vulnerable to this attack vector. Security teams should prioritize the deployment of Microsoft's patches across all affected SharePoint versions to close the authentication gap.

While the authentication bypass is the primary point of entry, the industry is monitoring for the emergence of full exploit chains. Because the flaw allows for total impersonation of privileged accounts, the primary risk remains the potential for unauthorized access to proprietary corporate data and the subsequent movement of attackers through the internal network.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.