• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

New SharePoint PoC Exploit Quickly Weaponized by Hackers

Published on: August 12, 2026
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 543 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
OpenAI Launches ChatGPT Desktop App for Linux in Preview
Apple Drops iOS 27 Public Beta 3 With Siri AI Upgrade
How to Prioritize CVEs Using Reachability Analysis
Robert A. Lee
Reviewed By
Robert A. Lee
Robert A. Lee
Senior Editor • 424 Articles
Robert A. Lee is a journalist at SQ Magazine who unpacks the fast-moving worlds of gaming and internet trends. He tracks everything from maj...
LATEST POSTS:
Udemy Statistics 2026: Revenue and Learner Data
Coursera Statistics 2026: Learners, Revenue and Growth Data
Reddit vs X Statistics 2026: Users and Revenue
Sharepoint Poc Exploit By Hackers
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A working exploit for CVE-2026-55040, a 9.1-severity SharePoint authentication bypass, is hitting live servers a day after Rapid7 published it, and thousands of servers remain exposed.

  • Attackers are running a fresh proof-of-concept exploit against real SharePoint servers, one day after Rapid7 published it.
  • The bug, CVE-2026-55040, lets an outsider forge a login token and act as any SharePoint user, including an administrator.
  • Microsoft fixed the flaw in July. Shadowserver still counts over 8,500 SharePoint servers reachable from the open internet.

Cybersecurity company Rapid7 published a proof-of-concept exploit for a critical Microsoft SharePoint authentication bypass on Tuesday, and attackers turned it against live systems within a day. Threat intelligence firm Defused said in a post on X that its SharePoint honeypots were already seeing hits from the released code. “Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots,” Defused wrote, adding that Rapid7 had published its technical writeup and proof-of-concept “yesterday.”

The flaw traces back to Microsoft’s July Patch Tuesday rollout, when the company fixed SharePoint Enterprise Server 2016 and SharePoint Server 2019 against the bug and the Cybersecurity and Infrastructure Security Agency (CISA) told network defenders to lock down internet-facing SharePoint deployments. Microsoft’s own advisory described the stakes in plain terms: “The authentication feature could be bypassed as this vulnerability allows impersonation. Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system.” The National Vulnerability Database rates the bug 9.1 out of 10, critical, under CWE-1390 for weak authentication.

🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots

The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday.

Track it live 👉… pic.twitter.com/Q8fbMyGq95

— Defused (@DefusedCyber) August 12, 2026

The four flaws chained inside SharePoint’s token check

Rapid7 researcher Stephen Fewer laid out the mechanism in a technical writeup published alongside the proof-of-concept code. SharePoint’s server-to-server authentication checks a JSON Web Token for identity claims, and that check runs through Microsoft’s SPJsonWebSecurityTokenHandlerV2 class. Fewer found the validation code sets RequireSignedTokens to false, so a token carrying no cryptographic signature at all passes through unchallenged.

Three more weaknesses compound the first. The handler resolves a signing certificate using a header value the attacker controls, and that value can point back to SharePoint’s own security token service certificate, one exposed on an unauthenticated metadata endpoint. Issuer validation then accepts that certificate because it isn’t registered in the specific trust list the code checks against. The final signature check only confirms a signature field is present. It never verifies the signature is cryptographically valid. Chained together, the four gaps let an unauthenticated attacker submit a self-issued token naming any user, including a domain administrator, and have SharePoint accept it.

Thousands of servers are still sitting exposed

Shadowserver, the nonprofit that tracks internet-exposed systems, counted over 8,500 Microsoft SharePoint servers reachable from the open internet this week, though it has no breakdown of how many are honeypots or already patched. That exposure sits alongside a second SharePoint bug, CVE-2026-45659, CISA confirmed this week is now being used in ransomware intrusions, months after Microsoft patched it as a lower-priority remote code execution flaw. Since November 2021, CISA has added 14 actively exploited SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, and eight of those were later tied to ransomware. SharePoint’s exposure sits well above the norm for on-premises enterprise software in CISA’s broader disclosure data.

Administrators running on-premises SharePoint who have not applied July’s patch should treat that as today’s priority, ahead of any deeper log review. Where the patch is already in, CISA’s guidance still applies: pull SharePoint Central Administration off the public internet, restrict farm and database traffic to systems that need it, and put any internet-facing SharePoint deployment behind a Layer 7 reverse proxy. These steps help reduce risk rather than guarantee it away. Security teams can also check IIS logs for unexplained hits on the metadata endpoint or unexpected bearer-token calls to /_api/contextinfo, the pattern Rapid7’s proof-of-concept walks through to establish a session.

CISA hasn’t listed it yet, but the pattern points that way

Microsoft has not flagged CVE-2026-55040 as exploited in the wild on its own advisory, and CISA has not added it to the Known Exploited Vulnerabilities catalog as of press time, though the honeypot activity Defused logged makes that listing likely if hits reach production servers. CVE-2026-45659 took months to move from a quiet patch to a confirmed ransomware tool. This one moved from proof-of-concept to honeypot hits in a single day, publish Tuesday, hit by Wednesday.

This article has been reviewed and fact-checked by Robert A. Lee. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity

References

  • CVE-2026-55040 Detail - National Vulnerability Database
  • Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
  • Defused post on X re: CVE-2026-55040 honeypot activity
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

Openai Launches Chatgpt Desktop App For Linux
Technology

OpenAI Launches ChatGPT Desktop App for Linux in Preview

Apple Drops Ios 27 Public Beta 3
Technology

Apple Drops iOS 27 Public Beta 3 With Siri AI Upgrade

Manus Will Delete User Data Meta Split
Artificial Intelligence

Manus Will Delete User Data August 23 in Meta Split

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

How to Prioritize CVEs Using Reachability Analysis
CISA Warns: SharePoint, SonicWall Flaws Fuel Ransomware
OpenAI Lifts GPT-5.6 Cyber Guardrails Days After Astra Halt

Table of Contents

  • The four flaws chained inside SharePoint’s token check
  • Thousands of servers are still sitting exposed
  • CISA hasn’t listed it yet, but the pattern points that way
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Gen Z Social Media Statistics
  • TikTok vs. Instagram Statistics
  • LLM Hallucination Statistics
  • Spotify User Statistics
  • Apple Customer Loyalty Statistics
  • Data Breach Tracker
  • Patch Tuesday Dashboard
  • AI Model Tracker
  • AI Funding Tracker
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. to 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
  • Accessibility Statement
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Technology
  • Artificial Intelligence
  • Gaming
  • Cybersecurity
Internet
Udemy Statistics
Udemy Statistics 2026: Revenue and Learner Data
Coursera Statistics
Coursera Statistics 2026: Learners, Revenue and Growth Data
Reddit vs X Statistics
Reddit vs X Statistics 2026: Users and Revenue
Apple Music Subscriber Statistics
Apple Music Subscriber Statistics 2026: Real User Insights
How Many Times Per Day Does The Average Person Check Social Media Statistics
How Many Times Per Day Does the Average Person Check Social Media Statistics 2026: Latest Insights
Outlook Statistics
Outlook Statistics 2026: Users, Market Share, Security & M365 Seats
Technology
Netflix vs. Hulu Statistics
Netflix vs Hulu Statistics 2026: Viewer Growth Data
TripAdvisor Statistics
TripAdvisor Statistics 2026: Revenue, Reviews, Viator and TheFork Data
Search Engine Statistics
Search Engine Statistics 2026: Market Share, Volume & AI Shift
NVIDIA Employee Count Statistics
NVIDIA Employee Count Statistics 2026: Headcount, R&D, and Revenue
Meta Employee Count Statistics
Meta Employee Count Statistics 2026: Headcount, Layoffs and AI Reallocation
Google Employee Count Statistics
Google Employee Count Statistics 2026: Headcount and Layoffs
Artificial Intelligence
AI Coding Statistics
AI Coding Statistics 2026: Adoption, Productivity and Market Data
How Much Content on Social Media Is AI Generated Statistics
How Much Content on Social Media Is AI Generated Statistics 2026: Hidden Truths
ChatGPT vs DeepSeek Statistics
ChatGPT vs DeepSeek Statistics 2026: Users, Benchmarks & Pricing
ChatGPT vs Claude vs Gemini vs Perplexity Statistics
ChatGPT vs Claude vs Gemini vs Perplexity Statistics 2026: Users, Revenue & Market Share
How Many People Work At Midjourney
How Many People Work At Midjourney 2026: Lean Team, Big Revenue
Grammarly AI Statistics
Grammarly AI Statistics 2026: Users, Revenue, Funding, Rebrand
Gaming
Roblox vs Minecraft Statistics
Roblox vs Minecraft Statistics 2026: Players, Revenue, Creators
Online Gambling Regulations Statistics
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Gamers Statistics
Gamers Statistics 2026: Players, Habits & Global Data
Cybersecurity
Signal Statistics
Signal Statistics 2026: Users, Finances and Encryption Adoption
Password Statistics
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics
API Security Breach Statistics 2026: Hidden Threats
Categories
  • Cybersecurity
  • Artificial Intelligence
  • Internet
  • Technology
  • Gaming
Cybersecurity
Sharepoint Poc Exploit By Hackers
New SharePoint PoC Exploit Quickly Weaponized by Hackers
Cisa Sonicwall Sharepoint Vulnerabilities Warning
CISA Warns: SharePoint, SonicWall Flaws Fuel Ransomware
Openai Lifts Gpt 5 6 Cyber Guardrails
OpenAI Lifts GPT-5.6 Cyber Guardrails Days After Astra Halt
Meta Ai Model Hacked Firm After Test Sandbox Failure
Meta Says Latest AI Model Hacked Other Company in Cybersecurity Testing
Brown Health Medical Group Data Breach
Brown Health Medical Group Data Breach Hits 311,000
Npm Attack Hits Keyv And Cacheable
npm Attack Hits Keyv and Cacheable Packages, Security Alert
Artificial Intelligence
Manus Will Delete User Data Meta Split
Manus Will Delete User Data August 23 in Meta Split
Anthropic Locks 191mw Riot Lease In 9 1b Compute Push
Riot Secures a Blockbuster $9.1B AI Data Center Deal
Yelp Puts Live Restaurant Booking On Chatgpt
Yelp Puts Live Restaurant Booking Directly Inside ChatGPT
Moonshot S Kimi K3 Escapes Critical Ai Safety Sandbox
Kimi K3 Exploits Sandbox Loophole in Alarming Test
Openai Drops Chatgpt Text Limits For Free Users
OpenAI Drops All ChatGPT Text Limits for Free Users
Meta Muse Code Launches Vs Codex And Claude Code
Meta Muse Code Launches With a Powerful Pricing Edge
Internet
Russia S Fsb Charges Telegram Founder Durov With Terrorism
Russia’s FSB Charges Telegram Founder Durov With Terrorism
Aws Cloudfront Outage Triggers Global 5xx Errors
AWS CloudFront Outage Triggers Global 5xx Errors
Whatsapp Launches Username Reservation Feature
WhatsApp Opens Username Reservations for Its 3 Billion Users
Chrome 149 Update Fixes Serious Vulnerabilities
Google Chrome 149 Fixes 18 Serious Security Flaws
Meta Hands Whatsapp Reins To Cred Founder Kunal Shah
Meta Hands WhatsApp Reins to CRED Founder Kunal Shah
Major X Outage Disrupts Users Worldwide
Major X Outage Disrupts Users Worldwide, Service Restored
Technology
Openai Launches Chatgpt Desktop App For Linux
OpenAI Launches ChatGPT Desktop App for Linux in Preview
Apple Drops Ios 27 Public Beta 3
Apple Drops iOS 27 Public Beta 3 With Siri AI Upgrade
Apple Ships Ios 26 6 1 Security Fix
Apple Ships iOS 26.6.1 Security Update for iPhone and iPads
Metabase Security Patch Zero Day Exploit
Metabase Urges Self-Hosted Users to Patch Critical SQL Flaw
Microsoft Launches Largest India Cloud Region In India
Microsoft Launches Largest India Cloud Region in Hyderabad
Google Maps Adds Bold New Agentic Ordering Tools
Google Maps Adds Bold New Agentic Ordering Tools
Gaming
Gta Vi Official Cover Art
GTA 6 Pre-Orders Start June 25, New Cover Art Unveiled
Epic Games Teases Unreal Engine 6 For Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Launched For Nintendo Switch 2 Edition
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Game Crosses 40m Downloads
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Pubg Black Budget Closed Alpha Launched
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter Strike 2 Skin Market Crashes After Valve Update
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Newsletter

Too much tech noise?

We respect your time. One high-signal briefing a week — tech, AI, and security. Nothing else.

Newsletter

The SQ Briefing

We track tech, AI, and security 24/7. You get a 5-minute weekly summary.