Critical SharePoint Vulnerability Exploited Globally; Patch Urgently Needed to Prevent Cyberattacks

August 11, 2026
Critical SharePoint Vulnerability Exploited Globally; Patch Urgently Needed to Prevent Cyberattacks
  • A critical vulnerability in Microsoft SharePoint, CVE-2026-55040, allows unauthenticated attackers to bypass authentication and read or modify data across affected sites, with a CVSS score of 9.1 and active exploitation in the wild.

  • The flaw was patched in July 2026, but exploitation began shortly after a public PoC was released, prompting rapid patching and heightened urgency for defense.

  • A second high-risk SharePoint flaw, CVE-2026-45659, is actively exploited in ransomware campaigns, driving immediate need to apply May and July updates across SharePoint Server 2016, 2019, and Server Subscription Edition.

  • Incident response guidance calls for containing affected servers, reviewing JWT logs, resetting credentials, revoking tokens, and restoring from trusted backups before reintegration.

  • The security community emphasizes moving quickly from disclosure to remediation, urging patch application and vigilant monitoring, with reference to additional security briefs and Pulse reports.

  • Advisories have not always specified active exploitation, but historical patterns show exploitation often follows public disclosures, underscoring the risk.

  • Threat actors have made at least a dozen exploitation attempts since July, including eight in mid-August, with sources across Hong Kong, Japan, the Netherlands, Taiwan, and the United States.

  • The exploitation landscape shows multiple attempts after the July 2026 Patch Tuesday, distributed geographically and targeting on-premises SharePoint 2016, 2019, and Subscription Edition.

  • IP-based activity comes from eight addresses tracing back to several countries, indicating a broad, distributed threat environment.

  • Post-exploitation activity includes PowerShell and cmd.exe use, lateral movement via Impacket and PsExec, scheduled tasks, and IIS configuration changes; ransomware campaigns may also alter Group Policy Objects to encrypt data.

  • Mitigation emphasizes applying July 2026 or newer patches, rotating keys and credentials, restarting IIS, auditing for webshells and malicious DLLs, tightening logging and SIEM, restricting external admin access, deploying WAFs, enabling AMSI/EDR, and practicing incident response drills.

  • A public PoC, including a Python script, forges tokens and demonstrates domain controller queries and SID enumeration, with full source code available.

Summary based on 7 sources


Get a daily email with more Tech stories

More Stories