A Critical Microsoft SharePoint Vulnerability is Being Exploited in Attacks, Leaving Thousands of Servers at Risk
A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-55040, has been published by cybersecurity company Rapid7. Just hours after its release, threat intelligence companies have already reported that the exploit is being used in attacks targeting exposed SharePoint servers online.
The CVE-2026-55040 vulnerability allows attackers to bypass authentication and perform operations as a SharePoint site user or administrator without valid privileges. This security flaw was patched by Microsoft as part of the July 2026 Patch Tuesday updates, but it appears many systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019 are still at risk.
According to threat intelligence company Defused, Rapid7’s exploit code has already been weaponized in attacks targeting its honeypots. This means that attackers have taken the published PoC exploit and adapted it for use in real-world attacks. With over 8,500 Microsoft SharePoint servers exposed online, as tracked by Internet threat watchdog Shadowserver, the potential for widespread exploitation is significant.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been warning network defenders to secure their SharePoint servers against this vulnerability since July 15. CISA recommends that security teams review Microsoft’s official SharePoint Server security-hardening guidance and block external access to SharePoint Central Administration. They also suggest placing servers behind a Layer 7 reverse proxy or similar application-layer security control when Internet exposure is required.
This attack highlights the ongoing issue of exploited vulnerabilities in Microsoft SharePoint. Since November 2021, CISA has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, with eight of them also used in ransomware attacks. This trend underscores the importance of regular patching and updating of software to prevent exploitation by attackers.
What makes this vulnerability particularly concerning is that once attackers have valid credentials, only a small percentage of their actions are blocked. According to The Blue Report 2026, overall prevention scores can hide what happens after initial access, with prevention dropping sharply once attackers are using valid credentials.
To protect against this and similar attacks, it’s essential for security teams to stay up-to-date on the latest vulnerabilities and patches. Regularly review your systems’ configuration and ensure that all software is patched and updated. Consider implementing application-layer security controls, such as reverse proxies or web application firewalls, to block external access to sensitive areas of your SharePoint servers.
By taking proactive steps to secure your systems, you can reduce the risk of exploitation by attackers and protect your organization from potential data breaches.
Source: Bleeping Computer — 2026-08-12