CRITICAL: SharePoint CVE-2026-55040 Exploited After Public PoC Release
Microsoft patched CVE-2026-55040 in July 2026, a CVSS 9.1 authentication bypass in on-premises SharePoint Server that chains four JWT validation failures to let an unauthenticated attacker forge tokens and impersonate any user, including administrators. Rapid7 published a working proof of concept on August 11 and honeypots recorded exploitation attempts roughly one day later. SharePoint Server 2016, 2019, and Subscription Edition are all affected.