CVE-2026-55040

Published Jul 14, 2026

Last updated 18 days ago

Exploit knownCVSS critical 9.1
Microsoft Office SharePoint
Jwt
Zero-day

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-55040 is an authentication bypass vulnerability affecting Microsoft SharePoint Server. This flaw stems from issues within the JSON Web Token (JWT) validation pipeline, allowing a remote, unauthenticated attacker to bypass the authentication process. By exploiting this vulnerability, an attacker can assume the identity of any SharePoint site user, provided they know the target user's Active Directory Security ID (SID) or User Principal Name (UPN). This authentication bypass can be chained with other vulnerabilities to achieve further compromise, such as unauthenticated remote code execution. The vulnerability was discovered by Rapid7 Labs during a zero-day research project.

Description
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Weak Authentication Vulnerability
Exploit added on
Aug 18, 2026
Exploit action due
Aug 21, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-1390

Social media

Hype score
Not currently trending
  1. 🚨 CISA listed a critical SharePoint auth bypass (CVE-2026-55040) in its KEV, often chained with CVE-2026-63520 for RCE. #VioletBridgeSecurity ensures identity & tech visibility. Is your team ready? 🔒 https://t.co/6s3sfJOjvC

    @VioletBridgeSec

    3 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ✨ SharePoint sotto attacco: la catena RCE non autenticata CVE-2026-55040 + CVE-2026-63520 Leggi il blog: https://t.co/ocsaRrQEIB https://t.co/DnxT2fiKS1

    @nuke86

    3 Sept 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Microsoft SharePoint の脆弱性 CVE-2026-55040/63520 の連鎖:サーバ制御奪取の恐れ https://t.co/IMSDjzzi73 Microsoft SharePoint Server において、Token 検証機能の不備や不要なクラスの制限不足が存在しています。脆弱性 CVE-2026-5504

    @iototsecnews

    3 Sept 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Technology Scout: Today's brief flags SharePoint mitigation work for SharePoint 2016, 2019, and Subscription Edition tied to CVE-2026-63520 and CVE-2026-55040. #AgenticAI #EnterpriseAI https://t.co/esaqyC81IM

    @MSRResearchTX

    31 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Technology Scout: Today's brief flags SharePoint mitigation work for SharePoint 2016, 2019, and Subscription Edition tied to CVE-2026-63520 and CVE-2026-55040. #AgenticAI #EnterpriseAI https://t.co/Mxc1gX25be

    @MSRResearchTX

    31 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. [MICROSOFT SHAREPOINT] — CVE-2026-55040: bypass de autenticación JWT permite suplantar a cualquier usuario. Impacto: un atacante no autenticado puede forjar un token JWT y hacerse pasar por cualquier usuario de SharePoint, incluido un administrador, aprovechando fallas en la

    @Soy_Nube_Negra

    30 Aug 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 𝗛𝗮𝗰𝗸𝗲𝗿𝘀 𝘁𝗮𝗿𝗴𝗲𝘁 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝗵𝗮𝗿𝗲𝗣𝗼𝗶𝗻𝘁 𝗥𝗖𝗘 𝗰𝗵𝗮𝗶𝗻 𝘄𝗶𝘁𝗵 𝗣𝗼𝗖 𝗲𝘅𝗽𝗹𝗼𝗶𝘁 Attackers are actively probing a chained exploit combi

    @ShadowSpanHQ

    30 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Microsoft SharePoint pre-auth RCE chain in the wild CVE-2026-63520 + CVE-2026-55040 = unauthenticated remote code execution. No creds needed. 8,500+ servers exposed. Exploitation started within hours of PoC release. Patch now → https://t.co/UvLALgYYWk

    @aratech_social

    30 Aug 2026

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.

    @InfosecDotWatch

    29 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【技術解説】パッチを待つな、「悪用済み」から塞げ — 8月のCISA KEV追加 CISAが8月、悪用確認済みとしてmacOS画面共有(CVE-2026-65400)、SharePoint(CVE-2026-55040)、VMware vCenter(CVE-2026-59310)をKEVに追加。共通点は「認証の抜

    @iss_kk_official

    29 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Microsoft SharePointのRCEチェーンを攻撃者らが狙う:CVE-2026-55040 - Codebook https://t.co/bK1UDoelYc

    @sec_trend

    28 Aug 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2026-63520 alone needs auth. CVE-2026-55040 alone is "just" a JWT bypass. together they're unauth RCE. severity lives in the glue, not either ticket. https://t.co/w0bISGne50

    @0xManan

    27 Aug 2026

    140 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 Attackers are probing a chain of two on-prem SharePoint flaws: CVE-2026-55040 can bypass authentication, while CVE-2026-63520 can potentially turn that access into RCE. Public PoCs exist. Patch. Reduce exposure. Monitor. Investigate. #Cybersecurity #SharePoint https://t.c

    @OBSYDIAPR

    27 Aug 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Share and share alike Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520 https://t.co/vk94Q747pB #decipher #deciphersec

    @DennisF

    27 Aug 2026

    159 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 SharePoint RCE Chain — Public PoCs Available CVE-2026-55040 → CVE-2026-63520 can be chained from authentication bypass to remote code execution. Public PoCs now exist for both flaws. https://t.co/CiNCJkZiQW #CVE #SharePoint #RCE #PoC #CyberSecurity #InfoSec https://t.

    @stem__shop

    27 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨Microsoft SharePointのRCEチェーンを攻撃者らが狙う:CVE-2026-55040、CVE-2026-63520 〜サイバーアラート8月27日〜 https://t.co/fHiBvWkERa

    @MachinaRecord

    27 Aug 2026

    157 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  17. Attackers are probing Microsoft SharePoint servers with a two-stage exploit chain that could lead to unauthenticated remote code execution on unpatched systems, according to threat intelligence provider Defused. The activity combines CVE-2026-55040, an authentication bypass in

    @rtehrani

    27 Aug 2026

    110 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Microsoft SharePointの脆弱性を狙う活動-CVE-2026-55040はKEV掲載、CVE-2026-63520の技術詳細も公開 https://t.co/R5W8bJk0aU #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    @securityLab_jp

    27 Aug 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Attackers are chaining CVE-2026-55040 and CVE-2026-63520 to hit unpatched Microsoft SharePoint servers with remote code execution. Public PoC exploits are available, and active probing has been seen. #SharePoint #CISA #Defused https://t.co/Pgoiqf6bmX

    @TweetThreatNews

    26 Aug 2026

    199 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Chained SharePoint flaws let attackers bypass JWT auth then trigger RCE on exposed servers. CVE-2026-55040 breaks token validation in the JWT pipeline. Rapid7's Stephen Fewer dropped the PoC August 11; unauthenticated requests can impersonate any site user or administrator.

    @SecureChap

    26 Aug 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Defused warned: "We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots." Both flaws have public PoC exploits (Rapid7, Aug 11; VulnCheck, Aug 24); CISA ordered federal agencies to patch weeks ago. Shadowserver counts 8,700+ SharePoint

    @XavierRiveraX

    26 Aug 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 CVE-2026-55040 - critical 🚨 Microsoft SharePoint Server - JWT Authentication Bypass > Microsoft SharePoint Server is vulnerable to an authentication bypass (CVE-2026-55040... 👾 https://t.co/01v440RYfR @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    26 Aug 2026

    790 Impressions

    5 Retweets

    15 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://t.co/w7WfofCvAh #CVE202655040 #CVE202663520 https://t.co/7Yysltrxm6

    @censysio

    25 Aug 2026

    3736 Impressions

    17 Retweets

    55 Likes

    27 Bookmarks

    0 Replies

    1 Quote

  24. Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520 https://t.co/vk94Q747pB #decipher #deciphersec

    @DennisF

    25 Aug 2026

    179 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 CRITICAL: A public exploit chain targeting Microsoft SharePoint is being actively probed in the wild. CVE-2026-55040 (authentication bypass) can be chained with CVE-2026-63520 (RCE) to achieve unauthenticated remote code execution on vulnerable SharePoint servers. @rapid7

    @ThreatWire_

    25 Aug 2026

    2186 Impressions

    0 Retweets

    5 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  26. 🚨🚨🚨 『when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers:』 Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://t.co/867lZwuPkF

    @autumn_good_35

    25 Aug 2026

    506 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  27. 🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain

    @DefusedCyber

    25 Aug 2026

    4701 Impressions

    9 Retweets

    42 Likes

    15 Bookmarks

    0 Replies

    1 Quote

  28. The @VulnCheckAI Initial Access team has a blog out now on chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://t.co/qNQpuszjdr

    @catc0n

    24 Aug 2026

    3856 Impressions

    21 Retweets

    55 Likes

    35 Bookmarks

    0 Replies

    1 Quote

  29. CVE-2026-55040 is now in CISA KEV. The CVSS 9.1 SharePoint authentication bypass needs no credentials or user interaction and can expose protected data over the network. Apply the July update, remove direct internet exposure and hunt token abuse. #CyberSecurity #SharePoint http

    @Altyence

    23 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🔴 New Actively-Exploited Vulnerability • CVE: CVE-2026-55040 • Vendor: Microsoft • Product: SharePoint • Flaw: Weak authentication bypass • Status: Actively exploited, not linked to ransomware Apply mitigations per vendor by 2026-08-21. Full report: 🔗 https://t

    @ido_cohen2

    21 Aug 2026

    1112 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  31. CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550

    @HOCupdate

    21 Aug 2026

    382 Impressions

    2 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  32. 🚨 August 20, 2026 Patches: CISA orders patching of 3 critical flaws by August 21. - Microsoft IKE (CVE-2026-33824, CVSS 9.8) - Adobe Commerce (CVE-2026-71362 CVSS 9.8) - SharePoint (CVE-2026-55040, CVSS 9.1) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/86S

    @CERT_UG

    20 Aug 2026

    103 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Rapid7's AI-guided agent found a SharePoint chain reaching unauthenticated RCE: CVE-2026-55040 (JWT bypass, 9.1) plus CVE-2026-63520 (BCS .NET type instantiation, 8.1). Read full blog here: https://t.co/IbfwDIqL5L https://t.co/37H4Qem6dY

    @DarkInvaderIO

    20 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824

    @BlackfireLu

    20 Aug 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. cisa kev just added four criticals. fceb deadline: aug 21. if you are short on cycles, order by exposure class: 1. sharepoint cve-2026-55040 - weak auth bypass, poc public 2. vcenter cve-2026-59310 - path traversal rce; reverse_ssh + babuk-derived ransomware (~361 ips reported)

    @cyberogz

    20 Aug 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. cisa kev just added four criticals. fceb deadline: aug 21. if you are short on cycles, order by exposure class: 1. sharepoint cve-2026-55040 - weak auth bypass, poc public 2. vcenter cve-2026-59310 - path traversal rce; reverse_ssh + babuk-derived ransomware (~361 ips reported)

    @cyberogz

    20 Aug 2026

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 CVE-2026-55040 — Critical SharePoint JWT authentication bypass (CVSS 9.1). Active exploitation observed. Patch immediately and investigate exposed servers. 🔗 https://t.co/V4vSUs2IpR #CyberSecurity #SharePoint #CVE #InfoSec https://t.co/QN6z23gb22

    @ThreatAft

    20 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 CVE-2026-55040 — Microsoft SharePoint Authentication Bypass CVSS 9.1 • No authentication required • Public PoC available • Active exploitation confirmed • Added to C https://t.co/EkZT030eem #CVE #CVE202655040 #SharePoint #Microsoft #CyberSecurity #InfoSec #Explo

    @stem__shop

    20 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h

    @CERT_UG

    19 Aug 2026

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs

    @TheHackersNews

    19 Aug 2026

    48061 Impressions

    90 Retweets

    317 Likes

    91 Bookmarks

    4 Replies

    3 Quotes

  41. CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Aug 18) CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free の脆弱性 CVE-2026-55040 Microsoft SharePoint

    @foxbook

    19 Aug 2026

    278 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日

    @__kokumoto

    18 Aug 2026

    634 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/iOSW67KcaP

    @MSRResearchTX

    17 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/OnPFKt3Gi9

    @MSRResearchTX

    17 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/FoPyCnoack

    @MSRResearchTX

    17 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/s0DpcYpC0d

    @MSRResearchTX

    17 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Rapid7'nin AI Ajanının Bulduğu SharePoint Açığı Artık Gerçek Saldırılarda Kullanılıyor Daha önce duyurduğumuz ve Rapid7'nin AI ajanının bulduğu SharePoint kimlik doğrulama atlatma açığı CVE-2026-55040, yayınlanan PoC kodu sayesinde artık gerçek saldırg

    @BTHaberler

    17 Aug 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 攻撃者が、概念実証(PoC)公開後にSharePointの重大な脆弱性を悪用(CVE-2026-55040) Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) #HelpNetSecurity (Aug 13) https://t.co/OwAtZfZT9A

    @foxbook

    17 Aug 2026

    242 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. ثغرتان في شيربوينت تتشابكان لتحقيق استغلال كامل عن بُعد دون مصادقة. المعرّف : CVE-2026-63520 درجة الخطورة : 8.1 (CVSS) - High السلسلة مع : CVE-2026-55040 → Unauthenticated RCE الحل : Appl

    @KasperskyDev

    16 Aug 2026

    296 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🚨 Microsoft SharePoint JWT token authentication bypass (CVE-2026-55040) and Windows Defender 0day vulnerability highlight the need for robust authentication and patching #ThreatIntel #CyberSecurity #CVE https://t.co/NOP2psjvvn

    @Npj8448

    15 Aug 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations