Particle.news
Download on the App Store

Public SharePoint PoC Triggers Active Exploitation of Critical JWT Bypass

The Rapid7 proof-of-concept has accelerated attacks against exposed on-premises SharePoint servers by shrinking the window between patch release and real-world abuse.

Overview

  • Rapid7 published a technical write-up and public proof-of-concept for CVE-2026-55040, a critical authentication bypass in SharePoint’s JWT validation, and defenders reported attackers began using that code shortly after its release.
  • Telemetry from multiple threat groups and honeypots recorded a spike in exploitation attempts on August 12–13, showing the PoC directly increased active probing of vulnerable farms.
  • Microsoft issued fixes in its July Patch Tuesday updates that block the JWT bypass and followed with August updates to address a chained remote code execution flaw (CVE-2026-63520).
  • Many on-premises installations remain at risk because Shadowserver tracks thousands of Internet-exposed SharePoint servers and July 14 marked end of support for SharePoint Server 2016 and 2019, complicating patching for those farms.
  • Agencies and defenders are urging immediate action — apply Microsoft’s updates, restrict external exposure, block Central Administration, use application-layer proxies, and hunt for signs of compromise to limit data theft and possible ransomware follow-on attacks.