Overview
- Rapid7 published a technical write-up and public proof-of-concept for CVE-2026-55040, a critical authentication bypass in SharePoint’s JWT validation, and defenders reported attackers began using that code shortly after its release.
- Telemetry from multiple threat groups and honeypots recorded a spike in exploitation attempts on August 12–13, showing the PoC directly increased active probing of vulnerable farms.
- Microsoft issued fixes in its July Patch Tuesday updates that block the JWT bypass and followed with August updates to address a chained remote code execution flaw (CVE-2026-63520).
- Many on-premises installations remain at risk because Shadowserver tracks thousands of Internet-exposed SharePoint servers and July 14 marked end of support for SharePoint Server 2016 and 2019, complicating patching for those farms.
- Agencies and defenders are urging immediate action — apply Microsoft’s updates, restrict external exposure, block Central Administration, use application-layer proxies, and hunt for signs of compromise to limit data theft and possible ransomware follow-on attacks.