CVE-2026-55040 โ Microsoft SharePoint Security-Feature Bypass
CVE-2026-55040 is a critical security-feature bypass (CVSS 9.1) in Microsoft SharePoint stemming from weak authentication. Exploitation allows impersonation that lets an attacker disclose and modify files on an affected SharePoint instance. It is being exploited in the wild by threat actors following Rapid7's release of a proof-of-concept earlier this week โ it is the fifth SharePoint vulnerability exploited in 2026.
Summary
Microsoft patched the flaw in July 2026. Threat actors began exploiting CVE-2026-55040 after a Rapid7 proof-of-concept was made public, with Defused Cyber reporting live in-the-wild exploitation. Because the flaw exposes and modifies files on an internet-facing SharePoint deployment, it directly triggers the rapid PoC-to-exploitation cycle characteristic of the week's patch-to-exploitation threat theme.
Affected products
- Microsoft SharePoint (internet-exposed deployments)
Remediation/Patches
- Microsoft patched the flaw in July 2026; organisations running SharePoint should apply the latest vendor patches and follow the Essential Eight prioritised patching discipline.
Sources
- The Hacker News โ Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- raw/digests/Cyber-Digest-2026-08-14