HackMyIP
← Back to News
2026-08-12 SecurityWeek

SharePoint Auth Bypass CVE-2026-55040 Exploited After Rapid7 PoC Release

VulnerabilityAuthenticationThreat Intel

Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass security features and impersonate site users or administrators. According to Microsoft, successful exploitation could enable file disclosure and unauthorized data modification through anonymous network connections. The flaw went from theoretical to actively exploited within a single week of public technical disclosure.

Rapid7 published full technical details and a working proof-of-concept (PoC) exploit for CVE-2026-55040 on August 11. Threat intelligence firm Defused reported on August 12 that its honeypots were already logging exploitation attempts leveraging Rapid7's PoC script. The rapid weaponization underscores how quickly attackers operationalize newly available exploit code. Defenders managing SharePoint on-premises deployments should verify patching immediately and audit logs for anomalous anonymous access patterns using tools such as our privacy checkup to assess exposure. Organizations can also scan external-facing SharePoint instances with our port scanner to identify unexpected open services that could indicate a foothold.

The threat escalates further with Rapid7's parallel discovery of CVE-2026-63520, a separate SharePoint flaw patched in Microsoft's August Patch Tuesday updates. When chained with CVE-2026-55040, the two vulnerabilities enable unauthenticated remote code execution (RCE) on vulnerable servers, giving attackers full control without any credentials. There are no current indications that CVE-2026-63520 is being exploited, but the existence of a public PoC for the authentication bypass component makes pre-emptive patching of the RCE flaw critical.

CVE-2026-55040 is the fifth SharePoint vulnerability to see in-the-wild exploitation this summer, following CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659. CISA has urged organizations to ensure SharePoint instances are fully patched, though the vulnerability has not yet been added to the agency's Known Exploited Vulnerabilities (KEV) catalog. No threat actor has been publicly attributed to the ongoing campaign. Given the authentication-bypass nature of these flaws, security teams should also verify that no credentials have been compromised by running an email breach checker against administrator accounts and reviewing SharePoint audit logs for signs of unauthorized access.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →