Microsoft SharePoint JWT Bypass Flaw CVE-2026-55040 Actively Exploited, Patch Urged
A critical vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, is being actively exploited in the wild following its disclosure around the July 2026 Patch Tuesday release. The flaw resides in SharePoint's JWT token validation chain used for service-to-service communication, allowing attackers to forge tokens by setting the algorithm to 'none' and bypassing signature verification entirely. Successful exploitation grants unauthenticated attackers full read and write access across all SharePoint sites on a compromised server. Telemetry from KEVIntel has recorded at least twelve distinct exploitation attempts, with activity observed across the United States, Hong Kong, Japan, the Netherlands, and Taiwan. Microsoft has released a security patch that removes the flawed JWT parsing logic, and security teams are advised to apply it immediately while restricting inbound service-to-service traffic as an interim measure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in