CVE-2026-55040
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- Published Jul 14, 2026
- CVSS 9.1 critical
- 69.5% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
- A fix is available
Affected software
In the news
- Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks SecurityWeek ·
- Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) VulnCheck Blog ·
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE The Hacker News ·
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain VulnCheck Blog ·
- Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 4 Canadian Centre for Cyber Security ·