CISA Adds Critical Microsoft SharePoint Auth Bypass (CVE-2023-29357) to KEV
Key Takeaways The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to patch a critical authentication bypass vulnerability in Microsoft...
Key Takeaways
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to patch a critical authentication bypass vulnerability in Microsoft SharePoint Server.
- Identified as CVE-2026-55040, the flaw allows unauthenticated attackers to gain unauthorized access to on-premises SharePoint environments.
- The vulnerability has been confirmed in active exploitation, prompting CISA to add it to its Known Exploited Vulnerabilities (KEV) catalog.
- Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. SharePoint Online is not impacted.
- Microsoft released patches in July 2026, and organizations are strongly advised to apply these updates immediately, especially to internet-facing deployments.
Critical SharePoint Authentication Bypass Under Active Exploitation
CISA has elevated a critical authentication bypass vulnerability within Microsoft SharePoint to its Known Exploited Vulnerabilities (KEV) catalog, following confirmation of its active exploitation in the wild. The flaw, tracked as CVE-2026-55040, poses a significant risk to organizations utilizing on-premises SharePoint deployments, enabling unauthenticated attackers to bypass security measures remotely.
Table Of Content
Understanding CVE-2026-55040
The vulnerability stems from a weakness in Microsoft SharePoint’s authentication mechanism, specifically within its handling of JSON Web Tokens (JWTs). This flaw, categorized under CWE-1390 (Authentication Bypass Using an Alternate Path or Channel), allows malicious actors to forge authentication tokens that SharePoint accepts as legitimate. Consequently, an attacker can impersonate valid users, including administrators, without requiring any prior credentials or session information.
This critical bypass grants unauthorized access to sensitive data, collaboration sites, configuration settings, and administrative functions, circumventing traditional password or session cookie theft methods. Technical analysis indicates the vulnerability resides in the JWT validation path, making internet-facing SharePoint instances particularly susceptible to attack.
Affected Versions and Remediation
The security vulnerability impacts several on-premises versions of SharePoint Server, including:
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Enterprise Server 2016
It is important to note that Microsoft’s cloud-based offering, SharePoint Online, is not affected by this specific issue. Microsoft addressed the vulnerability with security updates released during its July 2026 patch cycle. However, organizations that have not yet applied these fixes are now at heightened risk, especially given the public availability of proof-of-concept exploit code.
CISA officially added the vulnerability to the KEV catalog on August 18, 2026, mandating a remediation deadline of August 21, 2026, for federal agencies. While CISA’s notification does not explicitly mention ransomware deployment in conjunction with this CVE, its inclusion in the KEV catalog underscores the urgent need for immediate action by all organizations.
What You Should Do
- Immediate Patching: Apply Microsoft’s security updates from July 2026 without delay. Prioritize externally accessible SharePoint servers.
- Verify Full Deployment: Ensure that updates are completely deployed across all servers within your SharePoint farm. Incomplete patching can leave parts of the environment exposed.
- Review Logs for Suspicious Activity: Conduct a thorough review of SharePoint and identity logs for any indicators of compromise. Look for unexpected service-to-service authentication events, unusual administrator logins, unauthorized account changes, abnormal access to sensitive sites, and network traffic from untrusted sources targeting SharePoint endpoints.
- Forensic Triage: Understand that an attacker exploiting this flaw may appear in logs as a legitimate user. Implement robust forensic triage procedures to differentiate between valid and forged token usage.
- Adhere to CISA Guidance: Follow vendor instructions and CISA’s Binding Operational Directive 26-04 for risk-based patching. Assess the internet exposure of each SharePoint asset.
- Consider Removal: If effective mitigations cannot be immediately implemented, consider temporarily removing the vulnerable SharePoint product from service until it can be secured.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.