Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun exploiting CVE-2026-55040 (CVSS 9.1), a critical security-feature bypass in Microsoft SharePoint that enables impersonation and lets an attacker disclose and modify files. Microsoft patched the flaw in July 2026; Defused Cyber reports attackers exploiting it using a Rapid7 proof-of-concept released earlier in the week. It is the fifth SharePoint vulnerability exploited in 2026, after CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522.
Summary
The exploitation follows the public release of a Rapid7 proof-of-concept for the SharePoint authentication-bypass bug. Because it exposes and modifies files on an internet-exposed SharePoint instance, affected organisations face disclosure of sensitive SharePoint content and data integrity risks. The rapid PoC-to-exploitation cycle underscores SharePoint as a primary internet-exposed attack surface.
Impact
- File disclosure and data modification on affected SharePoint deployments
- Potentially triggers Australian Privacy Act Notifiable Data Breach obligations and NZ Privacy Act 2020 72-hour breach-notification windows
- Organisations running internet-exposed Microsoft estates are directly affected
Sector
Global (Macro)
Sources
- The Hacker News โ Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- raw/digests/Cyber-Digest-2026-08-14