< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Microsoft SharePoint vulnerability exploited in active attacks

Security researchers have identified a critical vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, which allows unauthenticated attackers to assume the identity of any user, including administrators. The flaw exists in the JSON Web Token (JWT) validation process, enabling attackers to bypass authentication by submitting tokens without valid signatures. This vulnerability has a CVSS score of 9.1 and affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Subscription Edition.

Threat intelligence indicates that proof-of-concept exploit code is already being used in active attacks. Furthermore, researchers discovered that this authentication bypass can be chained with a second vulnerability, CVE-2026-63520, to achieve unauthenticated remote code execution (RCE). This second flaw involves unsafe .NET type instantiation within SharePoint’s Business Connectivity Services.

Microsoft released patches for the initial authentication bypass in its July 2026 security updates. Administrators are advised to ensure these updates are installed to break the exploit chain. While the RCE vulnerability has also been addressed, specific build numbers for the August fix may still be pending public release. SharePoint Online is reportedly not affected by these specific on-premises vulnerabilities.

Entities

CISA · Microsoft · Rapid7 · SharePoint