🛑 Attackers are exploiting a SharePoint authentication bypass.
CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC.
See how the exploit works: https://t.co/7DxzQeCz9K