Publishing a technical writeup of a critical authentication bypass is normal, responsible security research. Publishing a working proof of concept alongside it hands every attacker who was waiting a finished tool, and this week that gap closed in hours, not weeks.
Four weaknesses chained into one forged admin token
CVE-2026-55040 sits in the JWT token validation pipeline of SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. Microsoft rates it 9.1 out of 10. The flaw chains four separate weaknesses in how SharePoint validates authentication tokens, and the end result is that an unauthenticated remote attacker can forge a valid JWT and impersonate any site user, including a site administrator, without ever supplying a password. Microsoft shipped the fix quietly as part of its 14 July Patch Tuesday round.
The researcher’s own proof of concept became the attack tool
Rapid7 published a detailed technical analysis of CVE-2026-55040, including a working proof of concept, and went further by demonstrating that the flaw can be chained with a second, still-unpatched remote code execution bug to move from impersonation to full unauthenticated RCE on the server. That second step has not been publicly detailed, but the first one did not need to be: threat intelligence firm Defused reported on 12 August that its SharePoint honeypots were recording exploitation attempts built directly on Rapid7’s published PoC. KEVIntel logged twelve exploitation attempts against tracked instances since 19 July, with eight of those landing on 12 and 13 August, a sharp acceleration that lines up exactly with the PoC going public.
Over 8,500 servers still exposed to the internet
Shadowserver’s scan this week counted more than 8,500 Microsoft SharePoint servers reachable from the open internet, with no reliable way yet to say how many are honeypots, already patched, or still sitting on the vulnerable JWT validation logic. CISA has not added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog as of this week, but the agency’s SharePoint hardening guidance already covers a dozen-plus flaws in the platform, and it has separately urged organisations to confirm their instances are current. No attribution for the current exploitation activity has surfaced publicly yet.
On-premises SharePoint is exactly where European organisations keep it
A large share of European government bodies, law firms, healthcare providers and financial institutions still run SharePoint on-premises rather than in Microsoft 365, specifically to keep control of where documents and identity tokens live. That same on-premises footprint is what puts them directly in the blast radius here: a forged admin token against an internet-facing SharePoint front end reaches every document library, workflow and connected system that server touches. Under NIS2 and GDPR, a known-exploited authentication bypass that sat unpatched for a month after a public fix was available is a difficult position to defend if it turns into an incident.
If your organisation runs on-premises SharePoint and needs help confirming you are past the July patch, hunting for signs this technique was already used against you, or reducing how much of your SharePoint estate is reachable from the open internet in the first place, contact Excello Digital. We help European organisations close the gap between a vendor’s patch release and attackers turning research into a working exploit.
