Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-18 ยท tags: [incident, sharepoint, microsoft, cve-2026-55040, exploited-in-the-wild, impersonation] ยท confidence: high ยท affected_sectors: [technology, government, enterprise] ยท au_impact: false

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun exploiting CVE-2026-55040 (CVSS 9.1), a critical security-feature bypass in Microsoft SharePoint that enables impersonation and lets an attacker disclose and modify files. Microsoft patched the flaw in July 2026; Defused Cyber reports attackers exploiting it using a Rapid7 proof-of-concept released earlier in the week. It is the fifth SharePoint vulnerability exploited in 2026, after CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522.

Summary

The exploitation follows the public release of a Rapid7 proof-of-concept for the SharePoint authentication-bypass bug. Because it exposes and modifies files on an internet-exposed SharePoint instance, affected organisations face disclosure of sensitive SharePoint content and data integrity risks. The rapid PoC-to-exploitation cycle underscores SharePoint as a primary internet-exposed attack surface.

Impact

  • File disclosure and data modification on affected SharePoint deployments
  • Potentially triggers Australian Privacy Act Notifiable Data Breach obligations and NZ Privacy Act 2020 72-hour breach-notification windows
  • Organisations running internet-exposed Microsoft estates are directly affected

Sector

Global (Macro)

Sources