Rewterz

Ivanti EPM Flaws Enable Remote Service Crashes

August 12, 2026

Hackers Exploit SharePoint Flaw After PoC Release

Severity

High

Analysis Summary

Threat actors have rapidly weaponized CVE-2026-55040, a critical Microsoft SharePoint authentication-bypass vulnerability with a CVSS score of high, shortly after Reseaher released a technical analysis and proof-of-concept (PoC). Researcher observed attackers using the Rapid7 PoC against exposed SharePoint honeypots, demonstrating that exploitation has moved from research into real-world attacks within hours. The vulnerability affects on-premises SharePoint deployments, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, while SharePoint Online is not affected.

The flaw resides in SharePoint's JWT authentication and token-validation pipeline, where multiple weaknesses can be chained to bypass authentication. Attackers can submit a JWT using alg: none, reference SharePoint's own security-token-service certificate through the x5t header, exploit insufficient validation of the certificate's trust relationship, and provide a non-empty but cryptographically invalid signature. Together, these issues allow an unauthenticated remote attacker to forge a valid-looking authentication token and impersonate arbitrary SharePoint users, potentially including site or domain administrators, without requiring a password or session cookie.

Researcher's PoC demonstrates the practical impact by using the forged token to interact with the target environment, query the domain controller, enumerate users through their SIDs, and identify the SharePoint administrator account for impersonation. Successful exploitation can therefore provide unauthorized access to SharePoint resources, allowing attackers to disclose files and modify data. Microsoft addressed CVE-2026-55040 in its July 2026 Patch Tuesday updates, but the vulnerability remains particularly dangerous because publicly exposed and unpatched SharePoint servers can be attacked remotely and exploitation is already occurring in the wild.

The risk is further elevated because CVE-2026-55040 can potentially be chained with CVE-2026-63520, a separate remote code execution vulnerability disclosed in August 2026, potentially allowing an attacker to progress from authentication bypass and user impersonation to full code execution on a vulnerable server. Organizations should therefore immediately apply the July and August 2026 SharePoint security updates, remove unnecessary internet exposure, restrict access to SharePoint administrative interfaces, and monitor authentication and service-to-service token activity for suspicious behavior. Given the rapid weaponization of the PoC, unpatched internet-facing SharePoint servers should be considered an urgent active-exploitation risk.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-55040

  • CVE-2026-63520

Remediation

  • Apply Microsoft’s July and August 2026 security updates to all affected on-premises SharePoint Server deployments immediately.
  • Prioritize CVE-2026-55040 patching on internet-facing SharePoint servers due to active exploitation.
  • Apply the security update for CVE-2026-63520 to prevent attackers from potentially chaining authentication bypass with remote code execution.
  • Remove unnecessary internet exposure of SharePoint servers and restrict access through VPNs, firewalls, or trusted IP ranges.
  • Monitor SharePoint authentication logs for unusual service-to-service token activity, failed authentication attempts, and unexpected administrative logins.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.