Rapid7’s PoC triggers active exploitation of the SharePoint authentication bypass (CVE-2026-55040)
On August 11, 2026 Rapid7 published the technical analysis and proof of concept for CVE-2026-55040, a SharePoint authentication bypass patched back in July. By August 13 attackers were already using the PoC against honeypots — here are the four weaknesses in the JWT validation chain and what to do about them.