{"id":17729,"date":"2026-08-14T09:05:23","date_gmt":"2026-08-14T09:05:23","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17729"},"modified":"2026-08-14T09:05:23","modified_gmt":"2026-08-14T09:05:23","slug":"attackers-exploit-sharepoint-authentication-bypass-after-public-poc-launch","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17729","title":{"rendered":"Attackers Exploit SharePoint Authentication Bypass After Public PoC Launch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 13, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Safety<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg_e1WsuZlqC_AfMpdI4wXB0wzIA6nGpPb5ktYmwO5jRhFqH2t56eGghhYAV7he6u0qTqiPacKD-Wf3c1vXxUmBV159KAObOJUTEDGdDafl9B0makdRgyKTUwWHZ5qxLpGbWRg33JJl_0KaY0K0fiWLaV2xghWX4KqUSeaoNgD9Z5ql1Q5VesZQyH-1eO7W\/s1600\/poc.jpg\" style=\"clear: left; display: block; float: left; padding: 1em 0px; text-align: center;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg_e1WsuZlqC_AfMpdI4wXB0wzIA6nGpPb5ktYmwO5jRhFqH2t56eGghhYAV7he6u0qTqiPacKD-Wf3c1vXxUmBV159KAObOJUTEDGdDafl9B0makdRgyKTUwWHZ5qxLpGbWRg33JJl_0KaY0K0fiWLaV2xghWX4KqUSeaoNgD9Z5ql1Q5VesZQyH-1eO7W\/s1600\/poc.jpg\"\/><\/a><\/div>\n<p>Menace actors have begun to take advantage of a newly disclosed Microsoft SharePoint vulnerability following the discharge of a proof-of-concept (PoC) code.<\/p>\n<p>The vulnerability in query is <strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/researcher-drops-new-windows-zero-day.html\" target=\"_blank\">CVE-2026-55040<\/a><\/strong> (CVSS rating: 9.1), which refers to a essential safety function bypass that stems from weak authentication. It was patched by Microsoft as a part of its July 2026 Patch Tuesday updates.<\/p>\n<p>&#8220;The authentication function might be bypassed as this vulnerability permits impersonation,&#8221; Microsoft mentioned in an advisory for the flaw final month. &#8220;Exploiting this vulnerability may permit an attacker to reveal recordsdata and modify knowledge, however the attacker can not affect the supply of the system.&#8221;<\/p>\n<p>In line with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/DefusedCyber\/status\/2087456962896093522\" target=\"_blank\">Defused Cyber<\/a>, menace actors are leveraging a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/08\/researchers-disclose-ai-assisted.html\" target=\"_blank\">PoC exploit<\/a> launched by Rapid7 earlier this week, as soon as once more indicating recent flaws are being quickly abused in real-world assaults.<\/p>\n<p><\/p>\n<p>It is value mentioning that CVE-2026-55040 is the fifth SharePoint vulnerability to be exploited this yr after <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/sharepoint-rce-cve-2026-45659-added-to.html\" target=\"_blank\">CVE-2026-45659<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/cisa-adds-exploited-sharepoint-rce-zero.html\" target=\"_blank\">CVE-2026-56164, CVE-2026-58644<\/a>, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/critical-sharepoint-rce-cve-2026-50522.html\" target=\"_blank\">CVE-2026-50522<\/a>.<\/p>\n<p>Profitable exploitation of CVE-2026-55040 can permit an unauthenticated attacker to sidestep authentication on a susceptible SharePoint server and carry out arbitrary operations as a SharePoint website person or administrator. The vulnerability, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.rapid7.com\/blog\/post\/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040\/\" target=\"_blank\">per Rapid7<\/a>, is because of &#8220;a number of points&#8221; within the JWT token validation pipeline.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"more\"\/><\/p>\n<p>Particularly, it chains 4 totally different weaknesses to permit an unauthenticated distant attacker to forge a sound JWT and impersonate any SharePoint website person. Rapid7 mentioned the problem resides in two totally different courses that implement the token parsing and validation logic for Bearer service-to-service (S2S) tokens &#8211;<\/p>\n<ul>\n<li>SPJsonWebSecurityTokenHandlerV2<\/li>\n<li>SPJsonWebSecurityBaseTokenHandlerV2<\/li>\n<\/ul>\n<p>Your entire chain could be exploited by an attacker as follows &#8211;<\/p>\n<ul>\n<li>Attacker sends a JWT with &#8220;alg: none&#8221; within the outer header, so no signature is required within the outer token.<\/li>\n<li>The actor token&#8217;s x5t header accommodates SharePoint&#8217;s personal STS certificates thumbprint, making it doable to resolve a signing key with no verification.<\/li>\n<li>The resolved certificates isn&#8217;t in TrustedSecurityTokenServices, permitting the issuer to be accepted.<\/li>\n<li>The actor token&#8217;s signature is a non-empty worth, e.g., AAAA, which isn&#8217;t verified.<\/li>\n<\/ul>\n<p>Rapid7&#8217;s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/sfewer-r7\/CVE-2026-55040\" target=\"_blank\">Python-based PoC<\/a> makes use of the cast JWT token to question a goal&#8217;s area controller, enumerate customers by SID, and auto-locate the SID for the person to discover a website administrator.<\/p>\n<p><\/p>\n<p>As of writing, it is unclear who&#8217;s behind the exploitation exercise or what their finish objectives are. Telemetry knowledge <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/kevintel.com\/CVE-2026-55040\" target=\"_blank\">captured by KEVIntel<\/a> reveals {that a} whole of 12 exploitation makes an attempt had been recorded since July 19, 2026. Out of those, eight passed off on August 12 and 13, 2026, indicating that the discharge of the PoC has performed a task in these efforts.<\/p>\n<p>The 12 exploitation makes an attempt have originated from eight distinctive IP addresses corresponding to 5 nations and areas, together with Hong Kong, Japan, the Netherlands, Taiwan, and the U.S. In mild of a spike in lively exploitation, SharePoint customers are suggested to maintain their cases up-to-date for optimum safety.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 13, 2026Vulnerability \/ Enterprise Safety Menace actors have begun to take advantage of a newly disclosed Microsoft SharePoint vulnerability following the discharge of a proof-of-concept (PoC) code. The vulnerability in query is CVE-2026-55040 (CVSS rating: 9.1), which refers to a essential safety function bypass that stems from weak authentication. It was patched by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17731,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1629,3369,210,776,4748,3280,922,2503],"class_list":["post-17729","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attackers","tag-authentication","tag-bypass","tag-exploit","tag-poc","tag-public","tag-release","tag-sharepoint"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17729"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17729\/revisions"}],"predecessor-version":[{"id":17730,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17729\/revisions\/17730"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17731"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-14 14:55:51 UTC -->