Hackers leverage new Microsoft SharePoint exploit in attacks

A Critical Microsoft SharePoint Vulnerity is Being Exploited in Real-World Attacks, Putting Thousands at Risk

A highly critical security vulnerability in Microsoft’s popular collaboration platform, SharePoint, has been found to be actively being used by hackers in real-world attacks. The flaw, tracked as CVE-2026-55040, allows attackers to bypass authentication and gain access to sensitive data without the need for valid credentials. This exploit was made public just yesterday by cybersecurity company Rapid7, but it appears that malicious actors have already begun using it to breach SharePoint servers.

The vulnerability affects SharePoint Enterprise Server 2016 and SharePoint Server 2019, which are used by thousands of organizations worldwide. Microsoft had patched the issue as part of its July Patch Tuesday updates, warning customers to apply the fix immediately. However, it seems that many users may not have taken heed of this warning, leaving their systems vulnerable to attack.

A proof-of-concept (PoC) exploit for CVE-2026-55040 was published by Rapid7 security researcher Stephen Fewer, along with a detailed technical write-up on the vulnerability. Threat intelligence company Defused has since reported that the exploit code has been used in attacks targeting its honeypots, which are decoy systems designed to attract and track malicious activity.

The fact that this vulnerability is being actively exploited in real-world attacks highlights the importance of keeping software up-to-date with the latest security patches. Microsoft’s own guidance warns that attackers could use this flaw to disclose files and modify data, although they would not be able to impact the availability of the system. However, as we have seen time and again, even seemingly minor vulnerabilities can have devastating consequences if left unpatched.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been warning network defenders about this vulnerability since July 15, advising them to secure their SharePoint servers against potential attacks. CISA recommends that users avoid exposing SharePoint servers directly on the Internet unless necessary and follow Microsoft’s official security-hardening guidance. It also suggests blocking external access to SharePoint Central Administration and restricting farm and database communication to required systems.

In recent years, we have seen a disturbing trend of hackers targeting Microsoft SharePoint vulnerabilities with alarming regularity. Since November 2021, CISA has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, including eight that were used in ransomware attacks. It’s essential for users to take proactive steps to protect themselves against these types of threats.

In light of this latest development, it’s crucial for organizations using Microsoft SharePoint to review their security posture and ensure they are running the latest patches. By doing so, they can significantly reduce the risk of falling victim to these types of attacks. If you’re a SharePoint user, take immediate action to patch your system and review your security settings. Remember, prevention is key – stay vigilant and stay secure!


Source: Bleeping Computer — 2026-08-12