Hackers Move Quickly To Exploit Critical Microsoft SharePoint Authentication Bypass

Hackers Move Quickly To Exploit Critical Microsoft SharePoint Authentication Bypass

By LinkedInEditors
Publication Date: 2026-08-13 09:00:00

Threat actors have begun targeting internet-facing Microsoft SharePoint servers with exploit code for a critical authentication-bypass vulnerability less than 24 hours after detailed technical research and a public proof of concept were released.

The vulnerability, tracked as CVE-2026-55040, affects supported on-premises editions of Microsoft SharePoint Server and carries a critical CVSS severity score of 9.1. It allows a remote attacker who has no valid credentials to forge authentication tokens and impersonate a SharePoint user—including, under the right conditions, a site administrator.

Threat-intelligence company Defused said on August 12 that its SharePoint honeypots had received attacks using the proof-of-concept code published a day earlier by Rapid7 security researcher Stephen Fewer. The activity provides…