Hackers exploit critical SharePoint flaw hours after security code released

Attackers are exploiting a critical Microsoft SharePoint authentication bypass vulnerability within hours of a proof-of-concept exploit being published, threat intelligence company Defused reported on Tuesday. The flaw, tracked as CVE-2026-55040, allows unauthenticated attackers to impersonate SharePoint users or administrators and access or modify files, according to cybersecurity researcher Stephen Fewer at Rapid7, who released the technical writeup and exploit code on Tuesday.
Microsoft patched the vulnerability in July 2026 updates and warned customers running SharePoint Enterprise Server 2016 and SharePoint Server 2019 to apply the fix. The U.S. Cybersecurity and Infrastructure Security Agency warned network defenders on July 15 to secure SharePoint servers and recommended blocking direct internet exposure or placing servers behind a Layer 7 reverse proxy. Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, Sergiu Gatlan reports for BleepingComputer.