Affected Systems

Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.

Exploitation Status

Active exploitation confirmed. Rapid7 published Python-based PoC exploit on August 11, 2026. KEVIntel telemetry shows 12 exploitation attempts from 8 unique IPs across 5 countries (Hong Kong, Japan, Netherlands, Taiwan, US) between July 19 and August 13, 2026, with 8 attempts occurring after PoC release.

Business Impact

CVSS 9.1 critical severity. Unauthenticated attackers can forge JWT tokens to bypass authentication and impersonate SharePoint administrators, enabling unauthorized file disclosure and data modification. This is the fifth actively exploited SharePoint vulnerability in 2026. Threat actors can enumerate domain users via SID and auto-locate site administrators. Availability is not impacted but confidentiality and integrity are severely compromised.

Urgency

🔴 Immediate

Recommended Actions

  • Apply Microsoft July 2026 Patch Tuesday updates to all SharePoint servers immediately
  • Audit SharePoint access logs for suspicious JWT authentication attempts and anomalous user impersonation activity since July 19, 2026
  • Monitor network traffic for connections from known malicious IPs associated with exploitation attempts (coordinate with threat intelligence feeds)
  • Review SharePoint site administrator accounts for unauthorized privilege escalation or account creation
  • Implement network segmentation to restrict SharePoint server exposure to untrusted networks and enforce strict firewall rules