THREAT OPS › CVEs › CVE-2026-55040
CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Vulnerability details
- Affected productsSharePoint
- KEV remediation due2026-08-21
Related reporting
- August 2026 CVE Landscaperecordedfuture
- Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520duo_decipher
- Windows IKE CVE-2026-33824 Added to CISA KEVsocradar_blog
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-55040 — Microsoft SharePoint: Microsoft SharePoint Weak Authentication Vulnerabilitycisa_kev
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Releasethehackernews
- Patch Tuesday - August 2026rapid7
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCEthehackernews
- CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)rapid7
- Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)rapid7
- CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilitiestenable
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)rapid7
- Patch Tuesday - July 2026rapid7
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewqualys
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiestalos
- The July 2026 Security Update Reviewzdi_blog