A public proof-of-concept for a critical SharePoint authentication bypass, CVE-2026-55040, is already being fired at honeypot servers just a day after release. For organisations still running on-premises SharePoint, this is the narrow window in which vulnerability management services earn their keep.
View the data behind this chart
| All actively exploited | Also used in ransomware | |
|---|---|---|
| CVE count | CVEs14 | CVEs8 |
What actually happened
Rapid7 researcher Stephen Fewer published a detailed technical write-up and working exploit code for CVE-2026-55040 on Tuesday, and it did not stay theoretical for long. By the next day, threat intelligence firm Defused reported the Rapid7 proof-of-concept was already being used against its SharePoint honeypots, according to BleepingComputer. The flaw sits in SharePoint's JWT token validation pipeline and allows an unauthenticated attacker to bypass authentication and impersonate a site user or administrator.
Microsoft patched the vulnerability during the July 2026 Patch Tuesday cycle, flagging SharePoint Enterprise Server 2016 and SharePoint Server 2019 as affected. Microsoft's own advisory notes the flaw "could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the system." Microsoft has not yet labelled it as exploited in the wild itself, though it did mark it an attractive target — and CISA moved on 15 July, ahead of any confirmed compromise, to urge defenders to lock down exposed servers.
The exposure problem: 8,500 servers and counting
Shadowserver's internet scanning currently counts more than 8,500 Microsoft SharePoint servers reachable online. Crucially, there's no clean breakdown of how many are patched, unpatched, or deliberately exposed honeypots — which means the real at-risk population could be smaller or significantly larger than the headline figure suggests. For UK IT leaders, that uncertainty is itself the risk signal: if you can't say with confidence which bucket your own estate falls into, you don't yet have visibility you can act on.
This echoes a separate, earlier SharePoint threat: in 2025, the NCSC confirmed active exploitation of a different vulnerability (CVE-2025-53770) against on-premises SharePoint Server products affecting UK organisations, explicitly distinguishing self-hosted deployments from SharePoint Online in Microsoft 365 — a distinction that matters enormously for procurement teams deciding where to focus patching effort and budget.
Ransomware is already circling SharePoint
This isn't SharePoint's first brush with weaponised exploitation, and the pattern is the real warning. CISA has flagged 14 actively exploited SharePoint vulnerabilities since November 2021, and eight of those were subsequently used in ransomware attacks. On the same day the CVE-2026-55040 PoC surfaced, CISA separately confirmed that a high-severity SharePoint remote code execution flaw, CVE-2026-45659, is now being exploited by ransomware gangs after being actively exploited since early July.
That ratio — roughly six in ten flagged SharePoint bugs eventually feeding ransomware campaigns — is the number that should sit in front of every UK security committee this week. Organisations without mature ransomware protection strategies layered behind their patching cadence are betting that this particular flaw breaks the historical trend.

CISA's hardening checklist, in UK-buyer terms
CISA's guidance following the July advisory is specific and actionable, and it maps directly onto procurement and architecture decisions rather than just patch scheduling. The agency recommends avoiding direct internet exposure of SharePoint servers unless business-critical, blocking external access to SharePoint Central Administration, and restricting farm and database traffic to only the systems that need it.
Where internet-facing SharePoint access genuinely can't be avoided, CISA recommends sitting the server behind a Layer 7 reverse proxy or equivalent application-layer control — a configuration many legacy on-premises deployments were never built with in mind. For estates running end-of-support or thinly-staffed SharePoint farms, this is often where third-party maintenance for patching closes the gap between what CISA recommends and what an internal team has bandwidth to implement this quarter.
- •Confirm whether your SharePoint Enterprise Server 2016 or SharePoint Server 2019 instances are internet-facing
- •Apply the July 2026 Patch Tuesday update for CVE-2026-55040 if not already deployed
- •Restrict Central Administration and farm/database access per CISA guidance
- •Place any unavoidably exposed servers behind a Layer 7 reverse proxy
Beyond the patch: resilience for the next SharePoint CVE
Patching CVE-2026-55040 closes today's door, but the eight-of-fourteen ransomware statistic confirms SharePoint will remain a recurring target. Organisations serious about understanding patch management as a continuous discipline — not a once-a-quarter scramble — are better placed to react in the hours after a PoC drops, rather than the days after honeypots start reporting hits.
It's also worth stress-testing the assumption that compromise stops at the SharePoint layer. Given how quickly authentication-bypass flaws have historically escalated into credential theft and lateral movement, pairing patch discipline with managed detection & response, a zero trust approach to internal SharePoint access, and verified Microsoft 365 backup solutions gives UK buyers a recovery path even if a determined actor gets there first.
