Hackers Actively Exploiting Microsoft SharePoint Vulnerability Following PoC Release
Brief
Threat actors have wasted no time weaponizing a newly disclosed Microsoft SharePoint authentication bypass, launching real-world attacks against internet-facing servers just hours after security firm Rapid7 published a technical breakdown and proof-of-concept exploit for the flaw.
The vulnerability, tracked as CVE-2026-55040 and carrying a critical CVSS score of 9.1, allows a remote, unauthenticated attacker to forge a valid authentication token and impersonate any SharePoint user, including a site administrator, without ever needing a password or session cookie.
Threat intelligence firm Defused confirmed the exploitation trend after observing suspicious activity hitting its SharePoint honeypots, warning that attackers were “now using the @rapid7 POC for CVE-2026-55040” against exposed systems.
