Back to Feed
VulnerabilitiesAug 12, 2026

SharePoint Vulnerability Exploited Shortly After PoC Release

SharePoint vulnerability CVE-2026-55040 is being exploited in the wild after PoC release.

Summary

A SharePoint vulnerability, CVE-2026-55040, patched by Microsoft in July, is now actively being exploited in the wild. The exploitation began shortly after a proof-of-concept exploit was released by Rapid7. This vulnerability allows attackers to bypass authentication and disclose files or modify data. Separately, CVE-2026-63520, another SharePoint flaw that can be chained with CVE-2026-55040 for unauthenticated RCE, was patched in August.

Full text

A SharePoint vulnerability patched last month is now being exploited in the wild, with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit. The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates. Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network. “Exploiting this vulnerability could allow an attacker to disclose files and modify data,” Microsoft said, adding, “In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection.” Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it to bypass authentication and perform operations as a SharePoint site user or administrator. The security firm also made a PoC script available. Threat intelligence firm Defused reported on August 12 that its honeypots have recorded exploitation attempts targeting CVE-2026-55040 and the attacks are leveraging the PoC released by Rapid7.Advertisement. Scroll to continue reading. Microsoft’s advisory still does not mention exploitation, but it’s not uncommon for the tech giant to only update its advisories days after attacks have been confirmed. Separately, Rapid7 on Tuesday reported discovering CVE-2026-63520, a SharePoint flaw that could be chained with CVE-2026-55040 to achieve unauthenticated remote code execution on servers. CVE-2026-63520 was addressed by Microsoft with its August Patch Tuesday updates, and there is no indication that it too is being exploited in attacks. Surge in SharePoint vulnerability exploitation CISA recently urged organizations to ensure that their SharePoint instances are up to date and protected in light of a new wave of attacks. At the time, CISA warned that CVE-2026-55040 could also be exploited in the wild. The agency has yet to add the vulnerability to its KEV catalog, which currently includes over a dozen SharePoint flaws. CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to light this summer, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659. However, there does not appear to be any public information on who is behind the exploitation of these weaknesses. Related: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Related: Fresh Windows Zero-Day Exploited in North Korean Cyberattacks Related: Zoom Patches Zero-Click Code Execution Vulnerability Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix ContactCisco Patches Firewall Zero-Day Exploited for DoS AttacksUS Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious ActivitiesOpenAI Unveils New Cybersecurity Model GPT-5.6-CyberMozilla Issues New Firefox GPG Key Following ExposureOpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack ConcernsNew Jersey, Alabama Join States Targeted in Water Cyberattacks Latest News Mindgard Raises $30 Million to Protect AI SystemsStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetWhatsApp Unveils New Scam Alert FeatureCeva Logistics Operations Disrupted by CyberattackChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities CombinedOver 2,500 Organizations Impacted by LiteLLM Supply Chain AttackFresh Windows Zero-Day Exploited in North Korean CyberattacksIvanti EPM Update Patches Remotely Exploitable Flaws Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveErika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.John Opala has joined Ralph Lauren as Chief Information Security Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-55040
  • cve — CVE-2026-63520
  • cve — CVE-2026-50522
  • cve — CVE-2026-58644
  • cve — CVE-2026-56164
  • cve — CVE-2026-45659

Entities

SharePoint (product)Microsoft (vendor)PoC exploit (product)Honeypots (product)Rapid7 (vendor)Defused (vendor)