A proof-of-concept exploit chain against on-premises Microsoft SharePoint Server is now being used in real attacks, and the gap between “researcher publishes a technique” and “attacker weaponizes it” was one day. That is the timeline researcher Defused reported for CVE-2026-55040, the authentication bypass at the center of the latest SharePoint exploitation wave, according to BleepingComputer’s Read more…