Attackers have begun exploiting a critical Microsoft SharePoint vulnerability after cybersecurity company Rapid7 published a proof-of-concept demonstrating the flaw. The vulnerability allows an attacker without prior privileges to bypass authentication and operate as a SharePoint site user or administrator. Tracked as CVE-2026-55040, the flaw affects the software’s JSON Web Token (JWT) validation pipeline. Microsoft patched it in its July 2026 Patch Tuesday updates and urged customers to update SharePoint Enterprise Server 2016 and SharePoint Server 2019. Microsoft said exploitation could allow an attacker to disclose files and modify data, though it could not affect system availability. Rapid7 security researcher Stephen Fewer published a detailed technical analysis and a proof-of-concept exploit on Tuesday. Threat intelligence company Defused later reported that attackers were using Rapid7’s exploit code against its SharePoint honeypots. “Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots,” the company said. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Shadowserver currently tracks more than 8,500 Microsoft SharePoint servers exposed online. It is unclear how many are honeypots or have already been patched. Microsoft has described the flaw as an attractive target for attackers but has not yet formally flagged it as successfully exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to protect their servers against potential CVE-2026-55040 attacks. It advised organizations to avoid exposing SharePoint servers directly to the internet unless necessary and to review Microsoft’s official SharePoint Server security-hardening guidance. Where internet exposure is required, CISA recommends placing servers behind a Layer 7 reverse proxy or a similar application-layer security control. It also advises blocking external access to SharePoint Central Administration and limiting farm and database communications to required systems. Since November 2021, CISA has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, eight of which were also used in ransomware attacks. On Tuesday, the agency confirmed that ransomware gangs are now exploiting a separate high-severity SharePoint remote code execution vulnerability, CVE-2026-45659, which has been actively exploited since early July. Organizations in Somalia using these SharePoint versions should verify that the July 2026 update is installed and apply CISA’s recommended controls to any internet-facing servers.