securityaffairs.com 8/13/2026, 9:21:16 AM · external

SharePoint Zero Day Flaw Exploited After Rapid7 PoC Release

SharePoint Zero Day Flaw Exploited After Rapid7 PoC Release
CyberSIXT Evidence Panel
Primary Source rapid7.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE article discusses the exploitation of a critical vulnerability in SharePoint (CVE-2026-55040), which allows unauthenticated users to impersonate administrators. The flaw, with a CVSS score of 9.1, was patched in July 2026, but public proof-of-concept (PoC) code released by Rapid7 on August 12 led to an immediate increase in exploitation attempts. Attackers utilize the vulnerability by forging JWT tokens without proper validation, enabling unauthorized access and data manipulation within SharePoint.

The pattern of exploitation following the publication of PoCs underscores the urgency for organizations to apply the necessary patches to prevent security breaches.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline