Critical severity9.1CISA KEVNVD Advisory· Published Jul 14, 2026· Updated Aug 19, 2026
CVE-2026-55040
CVE-2026-55040
Description
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*+ 2 more
- cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*range: <16.0.19725.20434
- cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040nvdPatchVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdExploitThird Party Advisory
- www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/nvdUS Government Resource
News mentions
20- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New StoriesThe Hacker News · Aug 27, 2026
- Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a PasswordCyber Security News · Aug 26, 2026
- Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Rapid7 Blog · Aug 24, 2026
- CISA Adds Microsoft SharePoint Weak Authentication Vulnerability to KEV ListCyber Security News · Aug 19, 2026
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe Hacker News · Aug 19, 2026
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesSecurityWeek · Aug 19, 2026
- Microsoft: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Aug 18, 2026
- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayHelp Net Security · Aug 16, 2026
- Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)Help Net Security · Aug 13, 2026
- Hackers Actively Exploiting Microsoft SharePoint Vulnerability Following PoC ReleaseCyber Security News · Aug 13, 2026
- Attackers Exploit SharePoint Authentication Bypass After Public PoC ReleaseThe Hacker News · Aug 13, 2026
- SharePoint Vulnerability Exploited Shortly After PoC ReleaseSecurityWeek · Aug 12, 2026
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Help Net Security · Aug 12, 2026
- Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code RemotelyCyber Security News · Aug 12, 2026
- Patch Tuesday - August 2026Rapid7 Blog · Aug 11, 2026
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active AttackThe Hacker News · Aug 11, 2026
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCEThe Hacker News · Aug 11, 2026
- CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Rapid7 Blog · Aug 11, 2026
- Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)Rapid7 Blog · Aug 11, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts