A SharePoint vulnerability patched final month is now being exploited within the wild, with the assaults beginning shortly after the discharge of a proof-of-concept (PoC) exploit.
The vulnerability, tracked as CVE-2026-55040, was fastened by Microsoft with its July Patch Tuesday updates.
Microsoft described it as a weak authentication situation that permits an attacker to bypass a safety function over a community.
“Exploiting this vulnerability may permit an attacker to reveal recordsdata and modify knowledge,” Microsoft stated, including, “In a network-based assault, an unauthenticated attacker may bypass authentication and make an nameless connection.”
Rapid7 disclosed the technical particulars of CVE-2026-55040 on August 11, exhibiting how a distant, unauthenticated attacker may exploit it to bypass authentication and carry out operations as a SharePoint web site person or administrator. The safety agency additionally made a PoC script out there.
Menace intelligence agency Defused reported on August 12 that its honeypots have recorded exploitation makes an attempt focusing on CVE-2026-55040 and the assaults are leveraging the PoC launched by Rapid7.
Microsoft’s advisory nonetheless doesn’t point out exploitation, however it’s not unusual for the tech big to solely replace its advisories days after assaults have been confirmed.
Individually, Rapid7 on Tuesday reported discovering CVE-2026-63520, a SharePoint flaw that might be chained with CVE-2026-55040 to realize unauthenticated distant code execution on servers.
CVE-2026-63520 was addressed by Microsoft with its August Patch Tuesday updates, and there’s no indication that it too is being exploited in assaults.
Surge in SharePoint vulnerability exploitation
CISA lately urged organizations to make sure that their SharePoint situations are updated and guarded in mild of a brand new wave of assaults.
On the time, CISA warned that CVE-2026-55040 may be exploited within the wild. The company has but so as to add the vulnerability to its KEV catalog, which at present contains over a dozen SharePoint flaws.
CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to mild this summer season, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.
Nevertheless, there doesn’t look like any public data on who’s behind the exploitation of those weaknesses.
Associated: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Associated: Contemporary Home windows Zero-Day Exploited in North Korean Cyberattacks
Associated: Zoom Patches Zero-Click on Code Execution Vulnerability








