Filed under: Cybersecurity — Patching — August 2026
What happened
Microsoft quietly patched a critical SharePoint flaw (CVE-2026-55040) back in July, but this week security researchers at Rapid7 published a working exploit for it — and attackers started using it within hours. The bug lets someone with no login at all forge a security token and pose as any user on the server, including an administrator, letting them read and change files. Most of the exploitation attempts recorded so far happened in just the last two days.
Why it matters to your business
This only hits on-premises SharePoint Server (Subscription Edition, 2019, or 2016) — not SharePoint Online inside Microsoft 365. But if your business or an IT vendor runs your own SharePoint server and it’s reachable from the internet, anyone who grabbed the published exploit code can now walk in as an admin, no password required. This is the third on-prem SharePoint bug this year to go from “patch released” to “actively exploited” within days.
What to do this week
Confirm the July 2026 security update is installed: in Central Administration, go to Upgrade and Migration > Check Product and Patch Installation Status (Subscription Edition needs KB5002882; 2019 and 2016 need KB5002883 or KB5002891). Then install August’s update too — it closes a second flaw that can be chained with this one for full remote code execution. If your SharePoint server is exposed directly to the internet, put it behind a VPN or an authenticated reverse proxy instead. Have someone check IIS and SharePoint ULS logs since August 11 for odd token-validation errors or admin logins you don’t recognize.
The bigger picture
On-prem SharePoint keeps producing high-severity bugs that get weaponized almost as fast as the fix ships, and each round means another scramble to patch and check for prior compromise. Moving that workload to SharePoint Online sidesteps this entire recurring fire drill. — Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Not sure if your SharePoint setup is exposed to the internet? Book a free consult — https://micro1tech.com/contact/