Microsoft SharePoint is the affected product in CVE-2026-55040, a critical authentication bypass vulnerability. The flaw allows unauthenticated attackers to forge JWT tokens and impersonate site users or administrators. SharePoint users are urged to apply the latest patches to protect against active exploitation.