HomeCyber BalkansSharePoint CVE-2026-55040 Currently Exploited

SharePoint CVE-2026-55040 Currently Exploited

Published on

spot_img

Major Security Flaw in Microsoft SharePoint Server Under Active Exploitation

A critical vulnerability, known as CVE-2026-55040, within Microsoft SharePoint Server Subscription Edition has come to light, raising significant concerns among security experts. This authentication bypass flaw, rated at a high CVSS score of 9.1, allows unauthenticated attackers to craft and use JSON Web Tokens (JWT) to impersonate legitimate SharePoint users and administrators. The situation escalated following the public release of proof-of-concept (PoC) code, which has already led to instances of active exploitation.

The vulnerability is rooted in a series of four weaknesses in the validation pipeline of SharePoint’s JWT token. According to an in-depth technical analysis conducted by the security firm Rapid7, attackers can exploit this flaw by sending a JWT that contains an "alg: none" parameter in its outer header. This conveniently eliminates the requirement for a valid signature, thereby enabling the attacker to manipulate SharePoint’s Security Token Service (STS). The issues compound as the exploit uses a trusted certificate thumbprint associated with the STS to resolve a signing key without going through adequate verification processes. In an astonishing twist, the attacker can send a non-empty but unverified signature, such as "AAAA," which SharePoint erroneously accepts as legitimate.

On August 12, 2026, Rapid7 publicly shared a detailed write-up along with the Python-based PoC code on GitHub. This PoC automates the exploit process, allowing attackers to efficiently query the target’s domain controller, enumerate users by their Security Identifier (SID), and automatically identify a site administrator account. Gaining administrator-level access subsequently allows these malicious actors to read sensitive documents, modify data within the SharePoint environment, and potentially leverage this access to infiltrate broader Microsoft 365 infrastructure. While Microsoft’s advisory states that attackers lack the ability to compromise system availability, the risks associated with unauthorized access and data manipulation cannot be understated.

As soon as the PoC code was released, security researchers at Defused reported immediate attempts to exploit the vulnerability against their SharePoint honeypots. Data from KEVIntel indicates that there have been 12 attempts to exploit the vulnerability since July 19, with a notable spike occurring on August 12-13. This increase reflects a pattern commonly observed in cybersecurity incidents where the availability of public exploit code significantly narrows the window of time between when a patch is available and when attackers begin their exploitation efforts. The attacks reportedly originated from eight different IP addresses spanning regions including Hong Kong, Japan, the Netherlands, Taiwan, and the United States.

In light of this alarming activity, organizations running SharePoint Server Subscription Edition are strongly advised to apply the July 2026 Patch Tuesday update without delay. The convergence of the vulnerability’s critical severity rating, the public exploit code, and confirmed active exploitation makes this a high-priority issue for remediation. Security teams should also conduct reviews of their SharePoint access logs for any suspicious authentication activities. It is also essential that they verify that all instances within their environment have been continuously updated with the necessary patches.

The rapid evolution of this situation underscores the importance of proactive measures in cybersecurity. Organizations must remain vigilant and prepared to act swiftly in the face of newly identified vulnerabilities, especially ones that pose an immediate risk due to active exploitation. The combination of robust security practices, systematic updates, and continuous monitoring can mitigate the adverse effects of such exploits, protecting both sensitive data and the overall integrity of Microsoft 365 environments.

Source link

Latest articles

The Future of the CISO Role in 2029

In the ever-evolving landscape of cybersecurity, the role of the Chief Information Security Officer...

Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware

Targeted Cryptocurrency Intrusion Reveals Vulnerabilities in Google-Hosted Apps Script Pages In a recently uncovered cyberattack,...

RingCentral Breach Exposes 1.6 Million Accounts

In July 2026, RingCentral, a prominent cloud-based business communications provider, experienced a significant data...

24 Malware Crypter Sellers Offer Paid Services for EDR Evasion and In-Memory Execution

The Emergence of a Subscription-Based Malware Evasion Market In recent months, a notable trend has...

More like this

The Future of the CISO Role in 2029

In the ever-evolving landscape of cybersecurity, the role of the Chief Information Security Officer...

Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware

Targeted Cryptocurrency Intrusion Reveals Vulnerabilities in Google-Hosted Apps Script Pages In a recently uncovered cyberattack,...

RingCentral Breach Exposes 1.6 Million Accounts

In July 2026, RingCentral, a prominent cloud-based business communications provider, experienced a significant data...