INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft SharePoint Exploit Used in Ransomware Attacks
| 2026-08-12 12:25 CRITICAL HIGHExecutive Summary AI-generated
The newly discovered vulnerability in Microsoft SharePoint, CVE-2026-55040, has been exploited by hackers to gain unauthorized access and modify data. This critical security flaw allows attackers to impersonate users without the necessary privileges, potentially leading to sensitive information disclosure or system compromise. The vulnerability was first reported by Rapid7 security researchers, who published a technical write-up and proof-of-concept code for the exploit. Microsoft has since patched the vulnerability as part of its July 2026 Patch Tuesday updates, warning customers to review their SharePoint Server configurations and ensure proper security hardening measures are in place.
Technical Mitigations AI-generated
* Implement a layered security approach, including application-layer security controls such as reverse proxies or firewalls to block external access to SharePoint Central Administration and restrict farm and database communication.
* Regularly update and patch all Microsoft SharePoint servers running Enterprise Server 2016 and Server 2019 to ensure that any known vulnerabilities are addressed before they can be exploited by attackers.
* Use secure coding practices, such as input validation and sanitization, when developing applications that interact with Microsoft SharePoint to prevent authentication bypass security flaws like CVE-2026-55040.
* Monitor Internet exposure of Microsoft SharePoint servers for signs of exploitation and take immediate action if necessary, including blocking external access or restricting farm and database communication.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825
CVE-2026-45659CVE-2026-45659
CVE-2026-55040CVE-2026-55040
Target & Sectors
Global Scope
Incident Timeline
November 2021
Ransomware gangs exploited a newly discovered high-severity Microsoft SharePoint remote code execution vulnerability.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, the cybersecurity agency has flagged
14 actively exploited Microsoft SharePoint vulnerabilities
, with eight of them also exploited in ransomware attacks.
general_metric
14 agency
Since November 2021, the cybersecurity agency has flagged
14 actively exploited Microsoft SharePoint vulnerabilities
, with eight of them also exploited in ransomware attacks.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
July 1
Threat actors used a newly discovered vulnerability in Microsoft SharePoint to target U.S. government agencies on July 1.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
tactic
T1588.006 - Vulnerabilities
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
attribution
KEV
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
attribution
Federal Civilian Executive Branch
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
attribution
FCEB
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
July 2026
Hackers used a newly discovered vulnerability in Microsoft SharePoint to target servers, exploiting the authentication feature which allows impersonation.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
organisation
SharePoint Enterprise
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
tactic
T1584.004 - Server
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
organisation
the @rapid7 POC
"Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned.
organisation
CVE-2026
"Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned.
organisation
Shadowserver
"
Internet threat watchdog Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online.
infrastructure
8,500 SharePoint servers
"
Internet threat watchdog Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online.
organisation
SharePoint Central Administration
It also recommended blocking external access to SharePoint Central Administration and restricting farm and database communication to the required systems.
July 15
Threat actors used CVE-2026-55040 to target U.S. network defenders on July 15.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-55040
Likely based on Microsoft's exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
warned network defenders
on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.
2026/08/11
Ransomware gangs began using a newly discovered Microsoft SharePoint remote code execution vulnerability to target systems.
Click on any entity below to view its context and source!
tactic
Ransomware
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
tactic
Remote Code Execution
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
attribution
CISA
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
2026/08/12
Threat actors used a newly discovered exploit in Rapid7's software to launch attacks against its honeypots.
2026/08/12
Hackers used a newly discovered exploit in Microsoft SharePoint to launch low-complexity attacks.
Click on any entity below to view its context and source!
organisation
Microsoft SharePoint
Microsoft SharePoint flaw now exploited in ransomware attacks.
Hackers leverage new Microsoft SharePoint exploit in attacks.
organisation
SharePoint
Tracked as
CVE-2026-45659
, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.
Tracked as
CVE-2026-55040
, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
organisation
CVE-2026
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
organisation
Shadowserver
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
infrastructure
8,500 SharePoint servers
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
organisation
JWT
Tracked as
CVE-2026-55040
, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
organisation
PoC
A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks.
organisation
Microsoft
It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.
organisation
SharePoint Enterprise
It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.
infrastructure
Windows
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
organisation
Windows Antimalware Scan Interface
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
organisation
Microsoft Defender Antivirus
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
Tactical Metrics
Metrics
infrastructure
8,500
Sharepoint Servers
Click for context!
"
Internet threat watchdog Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online.
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
Metrics
infrastructure
Windows
Affected Product
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
Intelligence Sources
BleepingComputer
2026-08-11
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer
BleepingComputer
2026-08-12
Hackers leverage new Microsoft SharePoint exploit in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-13T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
JWT
entity
9x
attribution
Attributing Entity
CISA
authority
8x
timeline
Temporal Reference
November 2021
date
4x
tactic
Cyber Operation Type
Impersonation
tactic
3x
vulnerability
Exploited CVE
CVE-2026-45659
cve
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
Contextual Telemetry
Context Block
7 METRICS
general metric
Agency
14
agency
infrastructure
Sharepoint Servers
8,500
sharepoint servers
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Reverse Proxy
7
reverse proxy
infrastructure
Affected Product
Windows
software
general metric
Unpatched
200
unpatched
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.