Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online — and one of the software's latest critical flaws already has proof‑of‑concept code turned into live attacks.
CVE-2026-55040: an authentication bypass in SharePoint
Security researcher Stephen Fewer and Rapid7 published a detailed technical write‑up and proof‑of‑concept (PoC) exploit for CVE-2026-55040, a critical Microsoft SharePoint vulnerability, on Tuesday. The flaw is an authentication bypass in the JWT token validation pipeline that "allows impersonation," according to Microsoft's advisory. Microsoft said that "Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system."
Microsoft issued a patch for the vulnerability as part of the July 2026 Patch Tuesday updates and specifically advised customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
Rapid7 PoC weaponized against honeypots, Defused reports
Within days of Rapid7 publishing the PoC, threat intelligence company Defused reported that attackers were using Rapid7's exploit code against its SharePoint honeypots. "Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned, indicating the PoC had been repurposed for active targeting.
Shadowserver's count of more than 8,500 exposed SharePoint servers provides a surface for opportunistic attackers, but the available data does not indicate how many of those hosts are patched or are honeypots. Microsoft has characterized the flaw as an "attractive target for attackers" but has not yet labeled CVE-2026-55040 as successfully exploited in the wild.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCISA and Microsoft: guidance and the wider SharePoint threat context
Likely following Microsoft's exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on July 15 urging defenders to secure SharePoint servers against potential CVE-2026-55040 attacks. CISA advised teams to avoid directly exposing SharePoint servers on the Internet unless necessary and to review Microsoft's official SharePoint Server security‑hardening guidance.
CISA's specific recommendations include blocking external access to SharePoint Central Administration, restricting farm and database communication to required systems, and—where Internet exposure is required—placing servers behind a Layer 7 reverse proxy or similar application‑layer security control. Since November 2021, CISA has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, eight of which were also exploited in ransomware attacks.
Separately, CISA confirmed on Tuesday that a high‑severity SharePoint remote code execution vulnerability, CVE-2026-45659—flagged as actively exploited since early July—is now being exploited by ransomware gangs. That confirmation places CVE-2026-55040 in a broader operational context where SharePoint flaws have repeatedly been leveraged by financially motivated actors.
Operational impact and defensive gaps highlighted by the Blue Report 2026
Microsoft's advisory limits the direct effects of CVE-2026-55040 to confidentiality and integrity: attackers "could allow an attacker to disclose files and modify data" but not impact availability. Yet the operational reality after an initial compromise can be more consequential. The Blue Report 2026 notes that "overall prevention scores can hide what happens after initial access" and warns that "once attackers are using valid credentials, prevention drops sharply." The report measures defenses technique by technique across 338 million simulations run in customer production environments, underscoring how credential misuse and valid‑session abuse can blunt traditional prevention controls.
What this means for security teams, affected enterprises, and CISA/network defenders
- Technologists and security teams: prioritize patching SharePoint Enterprise Server 2016 and SharePoint Server 2019 per Microsoft's July 2026 update, and consider the hardening steps CISA recommends—blocking Central Administration externally and restricting farm/database communications.
- Affected enterprises and procurement leaders: reassess any justification for direct Internet exposure of SharePoint servers; where exposure is necessary, implement an application‑layer control such as a Layer 7 reverse proxy and validate that vendor or in‑house hardening guidance has been applied.
- CISA and network defenders: continue to monitor exploit activity for CVE-2026-55040 and the related CVE-2026-45659, and treat Rapid7's PoC being weaponized against honeypots as an indicator that exploit code is in active circulation.
Microsoft issued a patch and CISA issued guidance, but Rapid7's published PoC and Defused's honeypot observations show the sequence security teams dread: a public technical write‑up, readily available exploit code, then opportunistic probing and exploitation. Whether defenders can close the window between disclosure and successful compromise will depend on rapid patching, reducing direct exposure, and controlling post‑access opportunities for credential and session abuse.




