Hackers Weaponize SharePoint Exploit Code Within Days of Release

A proof-of-concept exploit for a critical Microsoft SharePoint vulnerability is already being weaponized by attackers just days after its publication. Cybersecurity firm Rapid7 released the exploit code and a detailed technical writeup for CVE-2026-55040, which allows attackers to bypass authentication through the JWT token validation pipeline without requiring any prior privileges.

Threat intelligence company Defused confirms that hackers are actively targeting SharePoint honeypots using the published exploit. The flaw enables attackers to impersonate legitimate users or administrators, potentially disclosing sensitive files and modifying data. Microsoft patched the vulnerability in July 2026 for SharePoint Enterprise Server 2016 and SharePoint Server 2019, but many organizations have not yet applied the updates.

The Shadowserver watchdog currently identifies over 8,500 Microsoft SharePoint servers exposed online, though it remains unclear how many are vulnerable or already patched. CISA advises organizations to avoid exposing SharePoint servers directly to the internet, block external access to Central Administration, and follow Microsoft's official security-hardening guidance to reduce risk.

Read More at the original source →