SharePoint Flaw Exploited Soon After Public PoC Release
A vulnerability in Microsoft SharePoint that was patched in July is now being targeted in the wild, according to threat intelligence monitoring conducted after a public proof-of-concept exploit was re...
A vulnerability in Microsoft SharePoint that was patched in July is now being targeted in the wild, according to threat intelligence monitoring conducted after a public proof-of-concept exploit was released.
Tracked as CVE-2026-55040, the issue is described by Microsoft as a weak-authentication vulnerability. It can allow an unauthenticated, remote attacker to bypass an authentication control over a network. Successful exploitation may enable the attacker to access files, alter data, and carry out actions with the permissions of a SharePoint site user or administrator.
Microsoft addressed the flaw in its July 2026 security updates. However, its security advisory had not yet been updated to confirm active exploitation at the time of reporting. Microsoft advisories are sometimes revised after additional evidence is collected.
Security firm Rapid7 published technical analysis and a working proof-of-concept on August 11. The following day, threat intelligence company Defused said that its honeypots had observed attempts to exploit the vulnerability. The activity reportedly used techniques reflected in Rapid7’s publicly available code, suggesting that attackers moved quickly after the release.
Additional SharePoint vulnerability identified
Rapid7 also disclosed CVE-2026-63520, a separate SharePoint vulnerability that could potentially be combined with CVE-2026-55040 to achieve unauthenticated remote code execution on affected servers. Microsoft fixed CVE-2026-63520 in its August Patch Tuesday updates. At present, there is no reported evidence that attackers are exploiting that second flaw.
Broader wave of SharePoint attacks
The development comes amid increased exploitation of SharePoint weaknesses. The Cybersecurity and Infrastructure Security Agency recently urged organizations to apply available updates and secure their SharePoint deployments, warning that CVE-2026-55040 could be exploited. The agency had not yet added the flaw to its Known Exploited Vulnerabilities catalog.
CVE-2026-55040 is reportedly the fifth SharePoint vulnerability linked to exploitation during the summer, following CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659. Public reporting has not identified the groups responsible. Organizations using SharePoint should prioritize the relevant Microsoft updates, review exposed instances, and monitor authentication and file-access activity for suspicious behavior.
