CVE-2026-55040
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Description
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
In plain language
AI Act nowCVE-2026-55040 is a SharePoint Server security bypass that lets an attacker access (and possibly change) protected information over the network without logging in; if you run SharePoint Server 2016/2019/Subscription Edition, you should treat this as urgent and update to the fixed versions.
CVE-2026-55040 is a security feature bypass in Microsoft SharePoint Server (Enterprise 2016, Server 2019, and Subscription Edition) that can be reached over the network without authentication, allowing an attacker to obtain sensitive data and potentially modify information due to weak authentication.
What to do now
- Check which Microsoft SharePoint Server product you run (2016, 2019, or Subscription Edition) and confirm the currently installed patch level.
- If you are on an affected version, upgrade SharePoint to the fixed versions listed below.
- After updating, verify your SharePoint patch level matches the fixed version for your edition and review relevant access/activity logs for unusual requests.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
References
- September 2026 Patch Tuesday forecast: All we need is more timeen-us·Help Net Security· Exploited SharePoint rce
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Storiesen·The Hacker News· Roundup ReliaQuest ShinyHunters
- Hackers target Microsoft SharePoint RCE chain with PoC exploiten-us·BleepingComputer· Exploited Microsoft SharePoint rce
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitationen·The Hacker News· Exploited macOS zero-day
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilitiesen-us·SecurityWeek· Exploited Windows IKE patch-tuesday
- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayen-us·Help Net Security· Exploited Salesforce data-breach
- Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)en-us·Help Net Security· Exploited Microsoft SharePoint auth-bypass
- Microsoft выпустила патчи более чем для 400 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows Lazarus
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Releaseen·The Hacker News· Exploited Microsoft SharePoint auth-bypass
- SharePoint Vulnerability Exploited Shortly After PoC Releaseen-us·SecurityWeek· Exploited SharePoint auth-bypass
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-55040 and every CVE in our database. Create a free account — no credit card required.
Create Free Account