Hackers Actively Targeting SharePoint Flaw After Exploit Code Goes Public
Security researchers have confirmed active exploitation of CVE-2026-55040, a critical Microsoft SharePoint vulnerability with a CVSS score of 9.1, following the public release of proof-of-concept exploit code. The flaw allows attackers to bypass authentication controls due to weaknesses in how SharePoint verifies user identity, potentially giving unauthorised access to sensitive systems and data.
Microsoft addressed the vulnerability as part of its July 2026 Patch Tuesday security updates. However, once proof-of-concept code becomes public, attackers typically move quickly to exploit organisations that haven't yet applied the fix. This pattern is common in the cybersecurity world — patches are released, but many businesses delay updates, leaving a window of opportunity for cybercriminals.
For Australian small and medium businesses using SharePoint, whether on-premises or as part of a Microsoft 365 environment, this serves as a reminder that patching delays can have serious consequences. Authentication bypass vulnerabilities are particularly dangerous because they can allow attackers to skirt around login protections entirely, potentially leading to data theft, unauthorised access, or further compromise of connected systems.