July 15, 2026
- Rapid7 disclosed CVE-2026-55040, a SharePoint JWT authentication bypass allowing user impersonation, now fixed. A researcher notes it chains with the Flow2Shell bug (CVE-2026-47298) for a full pre-auth path. Rapid7, MSRC · Vulnerabilities & Exploits
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days