Attackers are starting to exploit a critical Microsoft SharePoint vulnerability after proof-of-concept (PoC) exploit code is made public. Multiple outlets report that threat actors take advantage of an authentication-bypass weakness that enables impersonation, allowing them to access and alter content.
The issue is tracked as CVE-2026-55040, rated CVSS 9.1. Microsoft patches the flaw as part of its July 2026 Patch Tuesday updates. Help Net Security quotes Microsoft saying the authentication feature could be bypassed, and that exploitation could enable attackers to disclose files and modify data, though it would not affect availability.
While both sources align on the existence of the vulnerability, its impact, and the timing of the patch, they differ slightly in emphasis. Help Net Security highlights that the PoC becomes public after Rapid7 releases exploit code. The Hacker News similarly links attacker activity to the PoC release and focuses on the authentication bypass nature of the bug.