The identified vulnerability, known as CVE-2026-55040, involves a significant weakness in the authentication process, stemming from inadequate security measures This article explores identity exploit activity. . This issue was addressed through Microsoft’s July 2026 Patch Tuesday updates.

Microsoft highlighted that the authentication feature could be circumvented due to this vulnerability allowing impersonation. Exploiting it would allow an attacker to access files and modify data, but not affect system availability. Defused Cyber reported that threat actors are utilizing a PoC exploit from Rapid7, indicating new flaws are being exploited in real-world attacks. The entire chain can be compromised by an attacker using the following steps: - A forged JWT token is used to query a target's domain controller.

  • Users' SIDs are enumerated through SID enumeration.
  • The attacker locates the user's SID and finds a site administrator, thereby gaining elevated privileges. The identity behind the exploit activity remains unknown, but it is evident from the captured telemetry data by KEVIntel that there have been 12 attempts since July 19, 2026. Specifically, eight of these were observed on August 12 and 13, 2026, suggesting that the PoC (Proof-of-Concept) release has been a catalyst for this activity.