UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

SharePoint RCE Exploit 2026: Why UK Firms Must Patch Now

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

A public proof-of-concept for a critical SharePoint authentication bypass, CVE-2026-55040, is already being fired at honeypot servers just a day after release. For organisations still running on-premises SharePoint, this is the narrow window in which vulnerability management services earn their keep.

SharePoint CVEs flagged by CISA since Nov 2021
20 CVEs15 CVEs10 CVEs5 CVEs0 CVEs14 CVEsAll actively exploited8 CVEsAlso used in ransomwareCVE count
View the data behind this chart
SharePoint CVEs flagged by CISA since Nov 2021
All actively exploitedAlso used in ransomware
CVE countCVEs14CVEs8

What actually happened

Rapid7 researcher Stephen Fewer published a detailed technical write-up and working exploit code for CVE-2026-55040 on Tuesday, and it did not stay theoretical for long. By the next day, threat intelligence firm Defused reported the Rapid7 proof-of-concept was already being used against its SharePoint honeypots, according to BleepingComputer. The flaw sits in SharePoint's JWT token validation pipeline and allows an unauthenticated attacker to bypass authentication and impersonate a site user or administrator.

Microsoft patched the vulnerability during the July 2026 Patch Tuesday cycle, flagging SharePoint Enterprise Server 2016 and SharePoint Server 2019 as affected. Microsoft's own advisory notes the flaw "could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system." Microsoft has not yet labelled it as exploited in the wild itself, though it did mark it an attractive target — and CISA moved on 15 July, ahead of any confirmed compromise, to urge defenders to lock down exposed servers.

The exposure problem: 8,500 servers and counting

Shadowserver's internet scanning currently counts more than 8,500 Microsoft SharePoint servers reachable online. Crucially, there's no clean breakdown of how many are patched, unpatched, or deliberately exposed honeypots — which means the real at-risk population could be smaller or significantly larger than the headline figure suggests. For UK IT leaders, that uncertainty is itself the risk signal: if you can't say with confidence which bucket your own estate falls into, you don't yet have visibility you can act on.

This echoes a separate, earlier SharePoint threat: in 2025, the NCSC confirmed active exploitation of a different vulnerability (CVE-2025-53770) against on-premises SharePoint Server products affecting UK organisations, explicitly distinguishing self-hosted deployments from SharePoint Online in Microsoft 365 — a distinction that matters enormously for procurement teams deciding where to focus patching effort and budget.

Ransomware is already circling SharePoint

This isn't SharePoint's first brush with weaponised exploitation, and the pattern is the real warning. CISA has flagged 14 actively exploited SharePoint vulnerabilities since November 2021, and eight of those were subsequently used in ransomware attacks. On the same day the CVE-2026-55040 PoC surfaced, CISA separately confirmed that a high-severity SharePoint remote code execution flaw, CVE-2026-45659, is now being exploited by ransomware gangs after being actively exploited since early July.

That ratio — roughly six in ten flagged SharePoint bugs eventually feeding ransomware campaigns — is the number that should sit in front of every UK security committee this week. Organisations without mature ransomware protection strategies layered behind their patching cadence are betting that this particular flaw breaks the historical trend.

Illustration: SharePoint RCE Exploit 2026: Why UK Firms Must Patch Now

CISA's hardening checklist, in UK-buyer terms

CISA's guidance following the July advisory is specific and actionable, and it maps directly onto procurement and architecture decisions rather than just patch scheduling. The agency recommends avoiding direct internet exposure of SharePoint servers unless business-critical, blocking external access to SharePoint Central Administration, and restricting farm and database traffic to only the systems that need it.

Where internet-facing SharePoint access genuinely can't be avoided, CISA recommends sitting the server behind a Layer 7 reverse proxy or equivalent application-layer control — a configuration many legacy on-premises deployments were never built with in mind. For estates running end-of-support or thinly-staffed SharePoint farms, this is often where third-party maintenance for patching closes the gap between what CISA recommends and what an internal team has bandwidth to implement this quarter.

  • Confirm whether your SharePoint Enterprise Server 2016 or SharePoint Server 2019 instances are internet-facing
  • Apply the July 2026 Patch Tuesday update for CVE-2026-55040 if not already deployed
  • Restrict Central Administration and farm/database access per CISA guidance
  • Place any unavoidably exposed servers behind a Layer 7 reverse proxy

Beyond the patch: resilience for the next SharePoint CVE

Patching CVE-2026-55040 closes today's door, but the eight-of-fourteen ransomware statistic confirms SharePoint will remain a recurring target. Organisations serious about understanding patch management as a continuous discipline — not a once-a-quarter scramble — are better placed to react in the hours after a PoC drops, rather than the days after honeypots start reporting hits.

It's also worth stress-testing the assumption that compromise stops at the SharePoint layer. Given how quickly authentication-bypass flaws have historically escalated into credential theft and lateral movement, pairing patch discipline with managed detection & response, a zero trust approach to internal SharePoint access, and verified Microsoft 365 backup solutions gives UK buyers a recovery path even if a determined actor gets there first.

Share
Key takeaways
  • CVE-2026-55040 is a critical JWT authentication bypass in on-premises SharePoint, patched in July 2026 but now actively targeted via a public Rapid7 PoC
  • Over 8,500 SharePoint servers are exposed online per Shadowserver, with no clarity on how many remain unpatched
  • CISA has tied 8 of 14 actively exploited SharePoint CVEs since 2021 to later ransomware campaigns, including the separate CVE-2026-45659 confirmed this week
  • CISA's hardening steps — restricting Central Administration, blocking unnecessary internet exposure, and using a Layer 7 reverse proxy — are the immediate priority alongside patching
Frequently asked

FAQs — SharePoint RCE Exploit 2026

Does CVE-2026-55040 affect SharePoint Online in Microsoft 365?

No. Reporting and NCSC guidance on SharePoint exploitation has consistently distinguished on-premises SharePoint Server deployments, such as SharePoint Enterprise Server 2016 and SharePoint Server 2019, from the cloud-hosted SharePoint Online service.

Has Microsoft confirmed CVE-2026-55040 is being exploited in the wild?

Microsoft has labelled the flaw an attractive target but had not, as of the BleepingComputer report, flagged it as successfully exploited in the wild. However, Defused reported that Rapid7's proof-of-concept exploit is already being used against SharePoint honeypots.

Is CVE-2026-45659 the same vulnerability as CVE-2026-55040?

No, they are separate flaws. CVE-2026-45659 is a high-severity remote code execution vulnerability that CISA confirmed is now being exploited by ransomware gangs.

What should UK organisations do first if they run on-premises SharePoint?

Confirm patch status against the July 2026 Patch Tuesday update, check whether SharePoint servers are directly internet-exposed, and apply CISA's hardening steps around Central Administration access and Layer 7 reverse proxies while a broader vulnerability management services review is scheduled.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111