Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities
August 19, 2026
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
August 19, 2026
China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor
August 19, 2026
Home/CyberSecurity News/CISA Adds Critical Microsoft SharePoint Auth Bypass (CVE-2023-29357) to KEV
CyberSecurity News

CISA Adds Critical Microsoft SharePoint Auth Bypass (CVE-2023-29357) to KEV

Key Takeaways The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to patch a critical authentication bypass vulnerability in Microsoft...

David kimber
David kimber
August 19, 2026 3 Min Read
2 0

Key Takeaways

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to patch a critical authentication bypass vulnerability in Microsoft SharePoint Server.
  • Identified as CVE-2026-55040, the flaw allows unauthenticated attackers to gain unauthorized access to on-premises SharePoint environments.
  • The vulnerability has been confirmed in active exploitation, prompting CISA to add it to its Known Exploited Vulnerabilities (KEV) catalog.
  • Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. SharePoint Online is not impacted.
  • Microsoft released patches in July 2026, and organizations are strongly advised to apply these updates immediately, especially to internet-facing deployments.

Critical SharePoint Authentication Bypass Under Active Exploitation

CISA has elevated a critical authentication bypass vulnerability within Microsoft SharePoint to its Known Exploited Vulnerabilities (KEV) catalog, following confirmation of its active exploitation in the wild. The flaw, tracked as CVE-2026-55040, poses a significant risk to organizations utilizing on-premises SharePoint deployments, enabling unauthenticated attackers to bypass security measures remotely.

Table Of Content

  • Key Takeaways
  • Critical SharePoint Authentication Bypass Under Active Exploitation
  • Understanding CVE-2026-55040
  • Affected Versions and Remediation
  • What You Should Do

Understanding CVE-2026-55040

The vulnerability stems from a weakness in Microsoft SharePoint’s authentication mechanism, specifically within its handling of JSON Web Tokens (JWTs). This flaw, categorized under CWE-1390 (Authentication Bypass Using an Alternate Path or Channel), allows malicious actors to forge authentication tokens that SharePoint accepts as legitimate. Consequently, an attacker can impersonate valid users, including administrators, without requiring any prior credentials or session information.

This critical bypass grants unauthorized access to sensitive data, collaboration sites, configuration settings, and administrative functions, circumventing traditional password or session cookie theft methods. Technical analysis indicates the vulnerability resides in the JWT validation path, making internet-facing SharePoint instances particularly susceptible to attack.

Affected Versions and Remediation

The security vulnerability impacts several on-premises versions of SharePoint Server, including:

  • SharePoint Server Subscription Edition
  • SharePoint Server 2019
  • SharePoint Enterprise Server 2016

It is important to note that Microsoft’s cloud-based offering, SharePoint Online, is not affected by this specific issue. Microsoft addressed the vulnerability with security updates released during its July 2026 patch cycle. However, organizations that have not yet applied these fixes are now at heightened risk, especially given the public availability of proof-of-concept exploit code.

CISA officially added the vulnerability to the KEV catalog on August 18, 2026, mandating a remediation deadline of August 21, 2026, for federal agencies. While CISA’s notification does not explicitly mention ransomware deployment in conjunction with this CVE, its inclusion in the KEV catalog underscores the urgent need for immediate action by all organizations.

What You Should Do

  • Immediate Patching: Apply Microsoft’s security updates from July 2026 without delay. Prioritize externally accessible SharePoint servers.
  • Verify Full Deployment: Ensure that updates are completely deployed across all servers within your SharePoint farm. Incomplete patching can leave parts of the environment exposed.
  • Review Logs for Suspicious Activity: Conduct a thorough review of SharePoint and identity logs for any indicators of compromise. Look for unexpected service-to-service authentication events, unusual administrator logins, unauthorized account changes, abnormal access to sensitive sites, and network traffic from untrusted sources targeting SharePoint endpoints.
  • Forensic Triage: Understand that an attacker exploiting this flaw may appear in logs as a legitimate user. Implement robust forensic triage procedures to differentiate between valid and forged token usage.
  • Adhere to CISA Guidance: Follow vendor instructions and CISA’s Binding Operational Directive 26-04 for risk-based patching. Assess the internet exposure of each SharePoint asset.
  • Consider Removal: If effective mitigations cannot be immediately implemented, consider temporarily removing the vulnerable SharePoint product from service until it can be secured.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000

Next Post

Microsoft ends support for Windows 11 24H2 Home and Pro editions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000
August 19, 2026
Critical macOS Screen Sharing Vulnerability Actively Exploited
August 19, 2026
MacSync Stealer Uses 30+ Domains to Steal Passwords and Sensitive Mac Data
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us