Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
After a proof-of-concept (PoC) code was released, threat actors started to take advantage of a recently discovered Microsoft SharePoint vulnerability.
CVE-2026-55040 (CVSS score: 9.1), a critical security feature bypass resulting from inadequate authentication, is the vulnerability in question. As part of their July 2026 Patch Tuesday upgrades, Microsoft fixed it.
Because this weakness permits impersonation, the authentication mechanism might be circumvented, Microsoft stated in a warning regarding the problem last month. An attacker may be able to reveal files and alter data by taking advantage of this vulnerability, although they are unable to affect the system's availability.
Threat actors are using a Proof of Concept (PoC) exploit that Rapid7 released earlier this week, accor...

