Full research report
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Executive assessment
The strongest conclusion is that CVE-2026-55040 is a critical, unauthenticated identity-boundary bypass affecting supported on-premises SharePoint Server editions before Microsoft's July fixed builds. Public Rapid7 code exists, and two separate operational sources report current attempts, including traffic said to match that PoC. Exploitation observations began before Rapid7's 11 August analysis, so publication appears to have lowered barriers and coincided with increased scanning rather than originating the entire activity. There is still no public evidence identifying the attackers, confirming production compromise or describing malware deployment and post-exploitation objectives.
What happened
Microsoft disclosed and fixed CVE-2026-55040 on 14 July 2026, while sensor reporting says exploitation attempts were first observed on 19 July. Rapid7 published detailed analysis and an accompanying PoC on 11 August; Defused reported traffic matching that PoC against SharePoint honeypots on 12 August, and KEV Intelligence showed continuing activity through 14 August. The four other CVEs are earlier exploited SharePoint vulnerabilities cited for context, not components of the CVE-2026-55040 authentication-bypass chain.
Affected scope
On-premises Microsoft SharePoint Enterprise Server 2016 before build 16.0.5561.1001, SharePoint Server 2019 before 16.0.10417.20175, and SharePoint Server Subscription Edition before 16.0.19725.20434 are affected. Published evidence does not identify particular victim organisations or sectors, although internet-accessible servers face the clearest exposure.
Technical assessment
CVE-2026-55040 is a network-reachable weak-authentication flaw in SharePoint's Bearer service-to-service JSON Web Token handling. Rapid7 found that four validation weaknesses can be combined to make an unauthenticated request appear to represent an arbitrary SharePoint user or administrator, permitting file disclosure and data modification without affecting availability. Public code substantially lowers the effort required to reproduce the bypass, but PoC availability alone does not establish successful compromise.
Recommended defensive actions
- Apply Microsoft's July 2026 SharePoint security updates and verify builds are at least 16.0.5561.1001 for 2016, 16.0.10417.20175 for 2019, or 16.0.19725.20434 for Subscription Edition.
- Inventory all on-premises SharePoint servers and validate which are reachable from untrusted networks.
- Restrict external access to SharePoint administrative and service endpoints until patch status has been verified.
- Hunt in SharePoint, reverse-proxy and identity logs for anomalous unauthenticated Bearer-token requests followed by unexpected user or administrator content access or modification.
- Review potentially exposed sites for unauthorised file access, account impersonation and data changes dating from at least 19 July 2026.
Uncertainties and evidence gaps
- No attacker identity, campaign name, malware family, victim organisation or operational objective has been established.
- Observed attempts and honeypot traffic do not prove that production systems were successfully compromised.
- Attempts were observed before Rapid7's 11 August publication, so the PoC may have amplified activity but did not initiate all exploitation.
- KEV Intelligence records public PoC coverage on 6 August, while Rapid7's analysis and linked code publication are dated 11 August; the exact first public availability of equivalent exploit code remains unclear.
- Microsoft's advisory recorded the vulnerability as not exploited at its original 14 July publication, but later sensor observations begin on 19 July; Microsoft had not updated that original-publication assessment on the page reviewed.
- The supplied reporting identifies CVE-2026-45659, but the reviewed sources did not establish its distinct role in this event.
- The supplied reporting identifies CVE-2026-50522, but the reviewed sources did not establish its distinct role in this event.
- The supplied reporting identifies CVE-2026-56164, but the reviewed sources did not establish its distinct role in this event.
- The supplied reporting identifies CVE-2026-58644, but the reviewed sources did not establish its distinct role in this event.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
Exploitation attempts against CVE-2026-55040 are observed in current sensor and honeypot reporting, and public PoC code is available; successful compromises and post-exploitation outcomes remain unconfirmed.
The investigation separated the focused CVE-2026-55040 event from the article's broader comparison with four earlier exploited SharePoint vulnerabilities. Microsoft and NVD established the affected versions and impact, while Rapid7 established the technical mechanism and public PoC. Independent sensor and honeypot reporting supports ongoing exploitation attempts, but not confirmed production compromise or attribution.
- What precise event and timeline did the supplied article allege?Read the supplied article and extracted its central claim, dates, cited PoC and exploitation sources.thehackernews.com โ
The article focuses on CVE-2026-55040 and alleges increased exploitation following Rapid7's PoC, while mentioning four earlier SharePoint CVEs only as context.
why This prevented the earlier vulnerabilities from being incorrectly treated as parts of the same technical chain.
- What does Microsoft confirm about affected products, impact and remediation?Opened Microsoft's vulnerability advisory and reviewed its summary, frequently asked questions and security-update table.msrc.microsoft.com โ
Microsoft released fixes on 14 July for SharePoint 2016, 2019 and Subscription Edition, describing unauthenticated impersonation, file disclosure and data modification without availability loss.
why This established the authoritative product scope, fixed builds and defensive baseline.
- What is the underlying weakness and practical significance?Read Rapid7's technical analysis while excluding procedural exploitation details.rapid7.com โ
Rapid7 found four weaknesses in SharePoint's service-to-service token validation that can be combined to impersonate an arbitrary site user or administrator without authentication.
why This explains why the flaw crosses a critical identity boundary and why exposed unpatched servers require urgent remediation.
- Is usable public exploit code genuinely available?Opened the linked public repository and verified that it contains a working-oriented Python PoC rather than only a placeholder description.github.com โ
The repository contains public code designed to exercise the CVE-2026-55040 authentication bypass.
why This confirms PoC availability but does not by itself prove real-world exploitation.
- Is there current exploitation evidence independent of the article?Reviewed the live KEV Intelligence record, its observation dates, aggregate telemetry and detection section.kevintel.com โ
The page reported 216 attempts, 13 unique attacker IPs, five countries and four sensors as of 14 August, with activity first observed on 19 July; raw request details were not publicly displayed.
why This supports ongoing attempted exploitation while limiting claims about successful compromise and exact request validity.
- Is there corroboration that attackers copied Rapid7's public PoC?Opened Defused's original 12 August honeypot report.x.com โ
Defused stated that attackers were using Rapid7's PoC against its SharePoint honeypots one day after Rapid7's technical publication.
why This directly supports PoC-matching activity, although honeypot traffic does not establish compromise of real organisations.
- Does an independent vulnerability authority corroborate severity and affected software?Reviewed the NVD record and its affected-configuration and reference sections.nvd.nist.gov โ
NVD records CWE-1390 weak authentication, a Microsoft CVSS score of 9.1 and the three affected SharePoint product lines, and links Microsoft, Rapid7 and the PoC repository.
why This independently corroborates the vulnerability identity, severity and technical scope.
- How do the four additional CVEs relate to the focused event?Parsed the current CISA Known Exploited Vulnerabilities catalogue for all five stated CVE identifiers.cisa.gov โ
CISA lists CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522 as exploited SharePoint vulnerabilities, including known ransomware use for CVE-2026-45659, but does not list CVE-2026-55040 in the catalogue snapshot reviewed.
why The four CVEs are valid historical SharePoint exploitation context, while the current CVE-2026-55040 assessment relies on separate sensor and honeypot evidence.
Research coverage
All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 6 registered sources supplied useful evidence (3 primary, 2 corroborating, 1 contextual and 0 PoC/exploit references). 55 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful โ or not |
|---|---|---|---|
| CISA KEVkev | ok1665 records | Primary evidence5 matched items | Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. Supplied a vendor or government advisory opened and verified during focused research. |
| NVDcve | ok900 records | Primary evidence1 matched items | Supplied a vendor or government advisory opened and verified during focused research. |
| The Hacker Newsnews | ok1 records | Primary evidence1 matched items | Published the source report used to frame and date the event. |
| CISA Alertsnews | ok empty0 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| Rapid7news | ok empty0 records | Corroborating1 matched items | Supplied independent analysis opened and verified during focused research. |
| FIRST EPSSepss | ok7640 records | Context4 matched items | Added exploitation-probability context; EPSS does not itself prove exploitation. |
| AlienVault OTXdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| BleepingComputernews | ok11 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| CIRCL CVEcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5324 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok2 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok682 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1008 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| DNSDumpster domain IOC enrichmentresearch | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok5 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok12 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok17 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok18 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok2 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Microsoft MSRCvendor_advisory | ok1590 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| MISP threat actor galaxyactor | ok0 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sigma Rulesresearch | ok2 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Sophos IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| ThreatFoxthreat_intelligence | ok100 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Unit42 IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 10 opened outside the registered collection
Vulnerability & exploitation8
Reporting-linked PoC claims1
Linked by reporting but not validated as PoC by the configured exploit indexes.
PoC & exploit code1
Public Python proof-of-concept for the SharePoint authentication bypass.
Vendor & gov advisories3
Microsoft's 14 July advisory identifies affected products, fixed builds and the unauthenticated impersonation impact.
Confirms the weak-authentication classification, critical severity and affected SharePoint configurations.
Confirms that the four other SharePoint CVEs cited by the article were previously exploited; CVE-2026-55040 was absent from the catalogue snapshot reviewed.
OSINT / dark-web chatter2
An 12 August report says attackers were using traffic matching Rapid7's PoC against SharePoint honeypots.
Current reporting shows attempts from 13 attacker IPs across five countries, first observed on 19 July and last observed on 14 August.
Analysis & research2
Technical analysis attributes the bypass to four weaknesses in SharePoint's service-to-service JSON Web Token validation logic.
Secondary reporting connected increased exploitation attempts with publication of Rapid7's PoC.