Active Exploitation Alert: SharePoint Authentication Bypass
- AUGUST 19TH, 2026
- 2min read
A critical authentication bypass vulnerability in Microsoft SharePoint Server is now under active exploitation following the public release of technical details and proof-of-concept exploit code. Organisations running on-premises SharePoint should treat this as an urgent security issue.
What Happened
CVE-2026-55040 (CVSS 9.1) is a flaw in SharePoint’s JWT token validation process that allows a remote, unauthenticated attacker to forge a valid authentication token and impersonate any SharePoint user, including an administrator. No credentials, prior access, or user interaction are required. Successful exploitation can allow attackers to access documents, modify data, and perform actions with administrative privileges across the SharePoint environment.
The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft addressed the vulnerability in the July 2026 SharePoint security updates. Once proof-of-concept exploit code became publicly available, attackers were able to rapidly automate scanning and exploitation of internet-facing SharePoint servers. This significantly reduces the time available for organisations to identify exposed systems and apply security updates.
How to Protect Your Organisation
1. Patch immediately: Apply the July 2026 SharePoint security updates across all affected servers and verify successful installation. Reduce internet exposure: Confirm whether SharePoint servers are accessible from the public internet and restrict access wherever possible.
2. Review authentication activity: Investigate unusual administrator activity, unexpected user impersonation events, and anomalous authentication behaviour.
3. Rotate SharePoint trust certificates: If compromise is suspected, rotate SharePoint server-to-server trust certificates and investigate for persistence.
4. Apply compensating controls: Use network segmentation, reverse proxies, web application firewalls, and enhanced monitoring for any server that cannot be patched immediately.
5. Monitor for active exploitation: Track Microsoft and trusted threat intelligence sources for indicators of compromise and emerging attack activity related to CVE-2026-55040.
Explore more CIL Advisories
Backdoor.ClickFix – The Fake Verification Trap
Hackers are increasingly exploiting human trust through a clever social engineering technique known as "ClickFix" (or "Pastejacking"). They trick Microsoft…
AUGUST 31ST, 2026
Read More
Defence Against Living-off-the-Cloud (LotC) & Trusted Infrastructure Abuse
Threat actors are abandoning easily blocked, newly registered domains in favour of hosting their Command and Control (C2) servers and…
AUGUST 24TH, 2026
Read More
AI-Powered Vulnerability Management: Exploits Faster Than Patches
Artificial intelligence is fundamentally changing how organisations identify, prioritise, and remediate vulnerabilities. Anthropic’s Project Glasswing has shown that advanced AI…
AUGUST 17TH, 2026
Read MoreNever miss a CIL Security Advisory
Stay informed with the latest security updates and insights from CIL.