A SharePoint vulnerability patched last month is now being exploited in the wild, with attacks beginning shortly after the release of a proof-of-concept (PoC) exploit.
The vulnerability, named CVE-2026-55040, was fixed by Microsoft with the July Patch Tuesday updates.
Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network.
“Exploitation of this vulnerability could allow an attacker to expose files and modify data,” Microsoft said, adding: “In a network-based attack, an unauthenticated attacker could bypass authentication and establish an anonymous connection.”
Rapid7 announced this technical details of CVE-2026-55040 on August 11 and shows how a remote, unauthenticated attacker can exploit it to bypass authentication and perform operations as a SharePoint site user or administrator. The security company also provided a PoC script.
Threat intelligence firm Defused reported on August 12 that its honeypots had been recording Exploitation attempts The attacks target CVE-2026-55040 and use the PoC published by Rapid7.
Note from Microsoft There’s still no mention of exploitation, but it’s not uncommon for the tech giant to update its advisories days after confirming the attacks.
Separately, Rapid7 reported the discovery on Tuesday CVE-2026-63520a SharePoint flaw that could be chained to CVE-2026-55040 to achieve unauthenticated remote code execution on servers.
CVE-2026-63520 was fixed by Microsoft with its August Patch Tuesday updates, and there is no evidence that it is also being exploited for attacks.
Increase in exploitation of SharePoint vulnerabilities
CISA recently urged organizations to ensure their SharePoint instances are up to date and protected in the face of a new wave of attacks.
At the time, CISA warned that CVE-2026-55040 could also be exploited in the wild. The agency has not yet included the vulnerability in its KEV catalog, which currently includes over a dozen SharePoint vulnerabilities.
CVE-2026-55040 is the fifth SharePoint vulnerability to be discovered this summer, following CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.
However, there appears to be no public information about who is behind the exploitation of these vulnerabilities.
Related: August 2026 Patch Tuesday: Microsoft fixes 421 CVEs, an exploited zero-day
Related: New Windows zero-day exploited in North Korean cyberattacks
Related: Zoom fixes zero-click code execution vulnerability
