Hackers Exploit Critical Microsoft SharePoint Vulnerability
A critical authentication-bypass vulnerability in Microsoft SharePoint has been exploited by hackers just over 24 hours after technical research and proof-of-concept code were released.
The vulnerability, tracked as CVE-2026-55040, affects supported on-premises editions of Microsoft SharePoint Server and carries a critical CVSS severity score of 9.1.
Rapid7 security researcher Stephen Fewer published the technical details and proof-of-concept code on August 11, after coordinating with Microsoft for a July 14 disclosure.
The vulnerability allows an attacker to forge authentication tokens and impersonate a SharePoint user, including under certain conditions, a site administrator. This can be particularly serious because it can be chained with a separate remote-code-execution flaw in SharePoint.