LIVE · cybersecurity feed
Live wire

jwt

CVE-2026-55040critical

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are actively exploiting a critical SharePoint vulnerability, CVE-2026-55040, following the public release of a proof-of-concept exploit. This flaw allows unauthenticated attackers to impersonate any user, including administrators, by forging JWT tokens. While Microsoft patched the vulnerability in July, organizations that have not yet applied the update remain at risk of unauthorized access and data manipulation.

CVE-2026-55040critical

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC) exploit. This security feature bypass allows unauthenticated attackers to impersonate users and potentially modify data by exploiting weaknesses in JWT token validation. Microsoft had previously patched this flaw in its July 2026 updates.