SharePoint Token Bypass Gets Weaponized
Attackers are reportedly using a public PoC for Microsoft SharePoint CVE-2026-55040, a JWT authentication bypass that can let them act as users or admins. Patch July updates and keep exposed SharePoint behind app-layer controls.