Active Exploitation Alert: SharePoint Authentication Bypass

  • AUGUST 19TH, 2026
  • 2min read
Active Exploitation Alert: SharePoint Authentication Bypass

A critical authentication bypass vulnerability in Microsoft SharePoint Server is now under active exploitation following the public release of technical details and proof-of-concept exploit code. Organisations running on-premises SharePoint should treat this as an urgent security issue.

What Happened

CVE-2026-55040 (CVSS 9.1) is a flaw in SharePoint’s JWT token validation process that allows a remote, unauthenticated attacker to forge a valid authentication token and impersonate any SharePoint user, including an administrator. No credentials, prior access, or user interaction are required. Successful exploitation can allow attackers to access documents, modify data, and perform actions with administrative privileges across the SharePoint environment.

The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft addressed the vulnerability in the July 2026 SharePoint security updates. Once proof-of-concept exploit code became publicly available, attackers were able to rapidly automate scanning and exploitation of internet-facing SharePoint servers. This significantly reduces the time available for organisations to identify exposed systems and apply security updates.

How to Protect Your Organisation

1. Patch immediately: Apply the July 2026 SharePoint security updates across all affected servers and verify successful installation. Reduce internet exposure: Confirm whether SharePoint servers are accessible from the public internet and restrict access wherever possible.

2. Review authentication activity: Investigate unusual administrator activity, unexpected user impersonation events, and anomalous authentication behaviour.

3. Rotate SharePoint trust certificates: If compromise is suspected, rotate SharePoint server-to-server trust certificates and investigate for persistence.

4. Apply compensating controls: Use network segmentation, reverse proxies, web application firewalls, and enhanced monitoring for any server that cannot be patched immediately.

5. Monitor for active exploitation: Track Microsoft and trusted threat intelligence sources for indicators of compromise and emerging attack activity related to CVE-2026-55040.

Never miss a CIL Security Advisory

Stay informed with the latest security updates and insights from CIL.

Active Exploitation Alert: SharePoint Authentication Bypass

Contact Us

Message Sent!

Thank you for reaching out. We have received your message and will get back to you shortly.

Check your email for a confirmation from us.

Start a project

Project Request Submitted!

Thank you for your interest. Our team will review your project details and reach out to you soon.

Check your email for a confirmation from us.