As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Rapid7 Labs discovered CVE-2026-55040, an authentication bypass vulnerability in Microsoft SharePoint that allows unauthenticated attackers to assume the identity of any known user by manipulating JWT token validation. The vulnerability has a CVSS score of 5.3 and can be chained with a second RCE vulnerability for complete system compromise; Microsoft will patch the RCE component in August 2026 while the authentication bypass fix is already available.
Why it matters: SharePoint administrators and security teams must prioritize patching this authentication bypass immediately, as it enables unauthorized access to sensitive business data and can be weaponized in combination with other vulnerabilities to achieve remote code execution across the enterprise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Rapid7 Labs discovered CVE-2026-55040, a JWT token validation flaw in Microsoft SharePoint that allows unauthenticated attackers to bypass authentication and assume the identity of any known user. The vulnerability has a CVSS score of 5.3 (Medium) and can be chained with a separate remote code execution flaw disclosed to Microsoft for patching in the August 2026 update cycle. The research was conducted for the Pwn2Own Berlin competition and demonstrates how medium-severity authentication bypasses can enable high-impact exploit chains.
Why it matters: SharePoint administrators and organizations running vulnerable instances must prioritize patching when Microsoft releases the August 2026 update, as unauthenticated attackers can impersonate users and gain administrative access to sensitive business data and workflows.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Rapid7 Labs disclosed CVE-2026-55040, a JWT token validation flaw in Microsoft SharePoint that allows unauthenticated attackers to bypass authentication and assume the identity of any known user. The vulnerability was discovered as part of a Pwn2Own Berlin competition entry and can be chained with a separate remote code execution flaw expected to patch in August 2026. Microsoft assigned the authentication bypass a CVSS v3.1 score of 5.3, though chaining it with RCE creates a critical attack path.
Why it matters: SharePoint administrators and Microsoft 365 operators must prioritize patching this active exploitation vulnerability immediately, as it grants unauthenticated remote access to sensitive collaboration platforms and can be weaponized for full system compromise when combined with secondary vulnerabilities.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Rapid7 Labs disclosed CVE-2026-55040, a JWT token validation flaw in Microsoft SharePoint that allows unauthenticated attackers to bypass authentication and assume the identity of any known user. The vulnerability was discovered as part of a Pwn2Own Berlin competition entry and can be chained with a separate remote code execution flaw expected to patch in August 2026. Microsoft assigned the authentication bypass a CVSS v3.1 score of 5.3, though chaining it with RCE creates a critical attack path.
Why it matters: SharePoint administrators and Microsoft 365 operators must prioritize patching this active exploitation vulnerability immediately, as it grants unauthenticated remote access to sensitive collaboration platforms and can be weaponized for full system compromise when combined with secondary vulnerabilities.
- Source published
- First seen by Cybersecurity Tracker