CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

Microsoft SharePoint Authentication Bypass Under Active Attack

June 26, 2026

Microsoft SharePoint is the affected product in CVE-2026-55040, a critical authentication bypass vulnerability. The flaw allows unauthenticated attackers to forge JWT tokens and impersonate site users or administrators. SharePoint users are urged to apply the latest patches to protect against active exploitation.