Attackers are actively exploiting a critical Microsoft SharePoint authentication bypass (CVE-2026-55040) after Rapid7 published a proof-of-concept exploit on Tuesday. Threat intelligence firm Defused confirmed the exploit code is already hitting honeypots, and CISA has flagged a related SharePoint flaw (CVE-2026-45659) as actively used in ransomware attacks.
The vulnerability lets an unauthenticated attacker bypass JWT token validation and operate as a SharePoint site administrator — no credentials needed. From there, chaining it with a second flaw (CVE-2026-63520) gives full remote code execution on the server. Microsoft patched both in July 2026, but with over 8,500 SharePoint servers still exposed online, many haven’t updated.
If your business runs SharePoint Server on-premises, this is urgent. SharePoint Online (part of Microsoft 365) is managed by Microsoft and isn’t affected, but on-prem instances of SharePoint Enterprise Server 2016 and SharePoint Server 2019 need the July security update applied immediately.
CISA’s hardening guidance is worth following even after patching: don’t expose SharePoint directly to the internet, place it behind a Layer 7 reverse proxy, restrict access to Central Administration, and limit farm and database communication to required systems only.
We see plenty of Australian businesses still running on-prem SharePoint — particularly in finance and professional services where data sovereignty requirements keep workloads local. If that’s you, check your patch status this morning.
Need help verifying your SharePoint deployment is patched and properly isolated? Get in touch with All IT Services — we can audit your setup and lock it down.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
