• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

SharePoint Vulnerability Exploited Shortly After PoC Launch

Admin by Admin
August 12, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A SharePoint vulnerability patched final month is now being exploited within the wild, with the assaults beginning shortly after the discharge of a proof-of-concept (PoC) exploit.

The vulnerability, tracked as CVE-2026-55040, was fastened by Microsoft with its July Patch Tuesday updates.

Microsoft described it as a weak authentication situation that permits an attacker to bypass a safety function over a community.

“Exploiting this vulnerability may permit an attacker to reveal recordsdata and modify knowledge,” Microsoft stated, including, “In a network-based assault, an unauthenticated attacker may bypass authentication and make an nameless connection.”

Rapid7 disclosed the technical particulars of CVE-2026-55040 on August 11, exhibiting how a distant, unauthenticated attacker may exploit it to bypass authentication and carry out operations as a SharePoint web site person or administrator. The safety agency additionally made a PoC script out there.

Menace intelligence agency Defused reported on August 12 that its honeypots have recorded exploitation makes an attempt focusing on CVE-2026-55040 and the assaults are leveraging the PoC launched by Rapid7.

Commercial. Scroll to proceed studying.

Microsoft’s advisory nonetheless doesn’t point out exploitation, however it’s not unusual for the tech big to solely replace its advisories days after assaults have been confirmed.

Individually, Rapid7 on Tuesday reported discovering CVE-2026-63520, a SharePoint flaw that might be chained with CVE-2026-55040 to realize unauthenticated distant code execution on servers.

CVE-2026-63520 was addressed by Microsoft with its August Patch Tuesday updates, and there’s no indication that it too is being exploited in assaults. 

Surge in SharePoint vulnerability exploitation

CISA lately urged organizations to make sure that their SharePoint situations are updated and guarded in mild of a brand new wave of assaults.

On the time, CISA warned that CVE-2026-55040 may be exploited within the wild. The company has but so as to add the vulnerability to its KEV catalog, which at present contains over a dozen SharePoint flaws. 

CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to mild this summer season, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.  

Nevertheless, there doesn’t look like any public data on who’s behind the exploitation of those weaknesses.

Associated: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Associated: Contemporary Home windows Zero-Day Exploited in North Korean Cyberattacks

Associated: Zoom Patches Zero-Click on Code Execution Vulnerability

Tags: ExploitedPoCreleaseSharePointshortlyVulnerability
Admin

Admin

Next Post
Runescape Congratulates Participant Who Reached Degree 99 Fishing Catching Solely Shrimp and Anchovies

Runescape Congratulates Participant Who Reached Degree 99 Fishing Catching Solely Shrimp and Anchovies

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Mentions, Citations, Click on Loss, and the Visitors Google Will not Present You

Mentions, Citations, Click on Loss, and the Visitors Google Will not Present You

January 26, 2026
Pest Management Advertising and marketing Company: website positioning Expertsalia

Pest Management Advertising and marketing Company: website positioning Expertsalia

July 15, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

August 9, 2026
Hasbro Information Breach Uncovered Worker Private Data

Hasbro Information Breach Uncovered Worker Private Data

August 30, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Is ClickUp Price It in 2026? My Trustworthy ClickUp Evaluate

Is ClickUp Price It in 2026? My Trustworthy ClickUp Evaluate

March 1, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Two Unpatched Citrix NetScaler RCE Zero-Days Beneath Energetic Exploitation

Two Unpatched Citrix NetScaler RCE Zero-Days Beneath Energetic Exploitation

September 28, 2026
Anthropic’s CEO is about to have dinner with President Trump

Anthropic’s CEO is about to have dinner with President Trump

September 28, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved