CVE Tools
Back to feed
Exploited in the wild SharePoint auth-bypass Microsoft info-disclosure

SharePoint Vulnerability Exploited Shortly After PoC Release

SecurityWeek·By Eduard Kovacs··2 min read
CVE Tools coverage

Active exploitation has been observed for CVE-2026-55040, a weak authentication vulnerability in Microsoft SharePoint that was patched during July Patch Tuesday. The attacks began immediately following the publication of a proof-of-concept exploit by Rapid7, allowing unauthenticated remote attackers to bypass security controls and access sensitive data. This incident marks the fifth SharePoint flaw targeted this summer, prompting urgent patching recommendations from CISA.