< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-13T11:39:48+05:30

Microsoft SharePoint Authentication Bypass Exploited Post-PoC Release

Threat actors are exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) following the release of a proof-of-concept (PoC) exploit, which allows authentication bypass via flawed JWT token validation. The vulnerability, patched in July 2026, enables unauthenticated attackers to impersonate users and access sensitive data.

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code.

The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates.

"The authentication

Read original article

*** END OF TRANSMISSION ***