CVE-2026-55040
Published Jul 14, 2026
Last updated 18 days ago
AI description
CVE-2026-55040 is an authentication bypass vulnerability affecting Microsoft SharePoint Server. This flaw stems from issues within the JSON Web Token (JWT) validation pipeline, allowing a remote, unauthenticated attacker to bypass the authentication process. By exploiting this vulnerability, an attacker can assume the identity of any SharePoint site user, provided they know the target user's Active Directory Security ID (SID) or User Principal Name (UPN). This authentication bypass can be chained with other vulnerabilities to achieve further compromise, such as unauthenticated remote code execution. The vulnerability was discovered by Rapid7 Labs during a zero-day research project.
- Description
- Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- sharepoint_server
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Microsoft SharePoint Weak Authentication Vulnerability
- Exploit added on
- Aug 18, 2026
- Exploit action due
- Aug 21, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-1390
- Hype score
- Not currently trending
🚨 CISA listed a critical SharePoint auth bypass (CVE-2026-55040) in its KEV, often chained with CVE-2026-63520 for RCE. #VioletBridgeSecurity ensures identity & tech visibility. Is your team ready? 🔒 https://t.co/6s3sfJOjvC
@VioletBridgeSec
3 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
✨ SharePoint sotto attacco: la catena RCE non autenticata CVE-2026-55040 + CVE-2026-63520 Leggi il blog: https://t.co/ocsaRrQEIB https://t.co/DnxT2fiKS1
@nuke86
3 Sept 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft SharePoint の脆弱性 CVE-2026-55040/63520 の連鎖:サーバ制御奪取の恐れ https://t.co/IMSDjzzi73 Microsoft SharePoint Server において、Token 検証機能の不備や不要なクラスの制限不足が存在しています。脆弱性 CVE-2026-5504
@iototsecnews
3 Sept 2026
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Today's brief flags SharePoint mitigation work for SharePoint 2016, 2019, and Subscription Edition tied to CVE-2026-63520 and CVE-2026-55040. #AgenticAI #EnterpriseAI https://t.co/esaqyC81IM
@MSRResearchTX
31 Aug 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Today's brief flags SharePoint mitigation work for SharePoint 2016, 2019, and Subscription Edition tied to CVE-2026-63520 and CVE-2026-55040. #AgenticAI #EnterpriseAI https://t.co/Mxc1gX25be
@MSRResearchTX
31 Aug 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[MICROSOFT SHAREPOINT] — CVE-2026-55040: bypass de autenticación JWT permite suplantar a cualquier usuario. Impacto: un atacante no autenticado puede forjar un token JWT y hacerse pasar por cualquier usuario de SharePoint, incluido un administrador, aprovechando fallas en la
@Soy_Nube_Negra
30 Aug 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
𝗛𝗮𝗰𝗸𝗲𝗿𝘀 𝘁𝗮𝗿𝗴𝗲𝘁 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝗵𝗮𝗿𝗲𝗣𝗼𝗶𝗻𝘁 𝗥𝗖𝗘 𝗰𝗵𝗮𝗶𝗻 𝘄𝗶𝘁𝗵 𝗣𝗼𝗖 𝗲𝘅𝗽𝗹𝗼𝗶𝘁 Attackers are actively probing a chained exploit combi
@ShadowSpanHQ
30 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft SharePoint pre-auth RCE chain in the wild CVE-2026-63520 + CVE-2026-55040 = unauthenticated remote code execution. No creds needed. 8,500+ servers exposed. Exploitation started within hours of PoC release. Patch now → https://t.co/UvLALgYYWk
@aratech_social
30 Aug 2026
59 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.
@InfosecDotWatch
29 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【技術解説】パッチを待つな、「悪用済み」から塞げ — 8月のCISA KEV追加 CISAが8月、悪用確認済みとしてmacOS画面共有(CVE-2026-65400)、SharePoint(CVE-2026-55040)、VMware vCenter(CVE-2026-59310)をKEVに追加。共通点は「認証の抜
@iss_kk_official
29 Aug 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft SharePointのRCEチェーンを攻撃者らが狙う:CVE-2026-55040 - Codebook https://t.co/bK1UDoelYc
@sec_trend
28 Aug 2026
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-63520 alone needs auth. CVE-2026-55040 alone is "just" a JWT bypass. together they're unauth RCE. severity lives in the glue, not either ticket. https://t.co/w0bISGne50
@0xManan
27 Aug 2026
140 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Attackers are probing a chain of two on-prem SharePoint flaws: CVE-2026-55040 can bypass authentication, while CVE-2026-63520 can potentially turn that access into RCE. Public PoCs exist. Patch. Reduce exposure. Monitor. Investigate. #Cybersecurity #SharePoint https://t.c
@OBSYDIAPR
27 Aug 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Share and share alike Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520 https://t.co/vk94Q747pB #decipher #deciphersec
@DennisF
27 Aug 2026
159 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SharePoint RCE Chain — Public PoCs Available CVE-2026-55040 → CVE-2026-63520 can be chained from authentication bypass to remote code execution. Public PoCs now exist for both flaws. https://t.co/CiNCJkZiQW #CVE #SharePoint #RCE #PoC #CyberSecurity #InfoSec https://t.
@stem__shop
27 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Microsoft SharePointのRCEチェーンを攻撃者らが狙う:CVE-2026-55040、CVE-2026-63520 〜サイバーアラート8月27日〜 https://t.co/fHiBvWkERa
@MachinaRecord
27 Aug 2026
157 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Attackers are probing Microsoft SharePoint servers with a two-stage exploit chain that could lead to unauthenticated remote code execution on unpatched systems, according to threat intelligence provider Defused. The activity combines CVE-2026-55040, an authentication bypass in
@rtehrani
27 Aug 2026
110 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft SharePointの脆弱性を狙う活動-CVE-2026-55040はKEV掲載、CVE-2026-63520の技術詳細も公開 https://t.co/R5W8bJk0aU #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
@securityLab_jp
27 Aug 2026
133 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining CVE-2026-55040 and CVE-2026-63520 to hit unpatched Microsoft SharePoint servers with remote code execution. Public PoC exploits are available, and active probing has been seen. #SharePoint #CISA #Defused https://t.co/Pgoiqf6bmX
@TweetThreatNews
26 Aug 2026
199 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Chained SharePoint flaws let attackers bypass JWT auth then trigger RCE on exposed servers. CVE-2026-55040 breaks token validation in the JWT pipeline. Rapid7's Stephen Fewer dropped the PoC August 11; unauthenticated requests can impersonate any site user or administrator.
@SecureChap
26 Aug 2026
87 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Defused warned: "We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots." Both flaws have public PoC exploits (Rapid7, Aug 11; VulnCheck, Aug 24); CISA ordered federal agencies to patch weeks ago. Shadowserver counts 8,700+ SharePoint
@XavierRiveraX
26 Aug 2026
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-55040 - critical 🚨 Microsoft SharePoint Server - JWT Authentication Bypass > Microsoft SharePoint Server is vulnerable to an authentication bypass (CVE-2026-55040... 👾 https://t.co/01v440RYfR @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
26 Aug 2026
790 Impressions
5 Retweets
15 Likes
5 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://t.co/w7WfofCvAh #CVE202655040 #CVE202663520 https://t.co/7Yysltrxm6
@censysio
25 Aug 2026
3736 Impressions
17 Retweets
55 Likes
27 Bookmarks
0 Replies
1 Quote
Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520 https://t.co/vk94Q747pB #decipher #deciphersec
@DennisF
25 Aug 2026
179 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: A public exploit chain targeting Microsoft SharePoint is being actively probed in the wild. CVE-2026-55040 (authentication bypass) can be chained with CVE-2026-63520 (RCE) to achieve unauthenticated remote code execution on vulnerable SharePoint servers. @rapid7
@ThreatWire_
25 Aug 2026
2186 Impressions
0 Retweets
5 Likes
4 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨 『when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers:』 Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://t.co/867lZwuPkF
@autumn_good_35
25 Aug 2026
506 Impressions
1 Retweet
1 Like
1 Bookmark
1 Reply
0 Quotes
🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain
@DefusedCyber
25 Aug 2026
4701 Impressions
9 Retweets
42 Likes
15 Bookmarks
0 Replies
1 Quote
The @VulnCheckAI Initial Access team has a blog out now on chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://t.co/qNQpuszjdr
@catc0n
24 Aug 2026
3856 Impressions
21 Retweets
55 Likes
35 Bookmarks
0 Replies
1 Quote
CVE-2026-55040 is now in CISA KEV. The CVSS 9.1 SharePoint authentication bypass needs no credentials or user interaction and can expose protected data over the network. Apply the July update, remove direct internet exposure and hunt token abuse. #CyberSecurity #SharePoint http
@Altyence
23 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 New Actively-Exploited Vulnerability • CVE: CVE-2026-55040 • Vendor: Microsoft • Product: SharePoint • Flaw: Weak authentication bypass • Status: Actively exploited, not linked to ransomware Apply mitigations per vendor by 2026-08-21. Full report: 🔗 https://t
@ido_cohen2
21 Aug 2026
1112 Impressions
1 Retweet
2 Likes
2 Bookmarks
0 Replies
0 Quotes
CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550
@HOCupdate
21 Aug 2026
382 Impressions
2 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 August 20, 2026 Patches: CISA orders patching of 3 critical flaws by August 21. - Microsoft IKE (CVE-2026-33824, CVSS 9.8) - Adobe Commerce (CVE-2026-71362 CVSS 9.8) - SharePoint (CVE-2026-55040, CVSS 9.1) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/86S
@CERT_UG
20 Aug 2026
103 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Rapid7's AI-guided agent found a SharePoint chain reaching unauthenticated RCE: CVE-2026-55040 (JWT bypass, 9.1) plus CVE-2026-63520 (BCS .NET type instantiation, 8.1). Read full blog here: https://t.co/IbfwDIqL5L https://t.co/37H4Qem6dY
@DarkInvaderIO
20 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824
@BlackfireLu
20 Aug 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
cisa kev just added four criticals. fceb deadline: aug 21. if you are short on cycles, order by exposure class: 1. sharepoint cve-2026-55040 - weak auth bypass, poc public 2. vcenter cve-2026-59310 - path traversal rce; reverse_ssh + babuk-derived ransomware (~361 ips reported)
@cyberogz
20 Aug 2026
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
cisa kev just added four criticals. fceb deadline: aug 21. if you are short on cycles, order by exposure class: 1. sharepoint cve-2026-55040 - weak auth bypass, poc public 2. vcenter cve-2026-59310 - path traversal rce; reverse_ssh + babuk-derived ransomware (~361 ips reported)
@cyberogz
20 Aug 2026
97 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-55040 — Critical SharePoint JWT authentication bypass (CVSS 9.1). Active exploitation observed. Patch immediately and investigate exposed servers. 🔗 https://t.co/V4vSUs2IpR #CyberSecurity #SharePoint #CVE #InfoSec https://t.co/QN6z23gb22
@ThreatAft
20 Aug 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-55040 — Microsoft SharePoint Authentication Bypass CVSS 9.1 • No authentication required • Public PoC available • Active exploitation confirmed • Added to C https://t.co/EkZT030eem #CVE #CVE202655040 #SharePoint #Microsoft #CyberSecurity #InfoSec #Explo
@stem__shop
20 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h
@CERT_UG
19 Aug 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs
@TheHackersNews
19 Aug 2026
48061 Impressions
90 Retweets
317 Likes
91 Bookmarks
4 Replies
3 Quotes
CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Aug 18) CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free の脆弱性 CVE-2026-55040 Microsoft SharePoint
@foxbook
19 Aug 2026
278 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日
@__kokumoto
18 Aug 2026
634 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/iOSW67KcaP
@MSRResearchTX
17 Aug 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/OnPFKt3Gi9
@MSRResearchTX
17 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/FoPyCnoack
@MSRResearchTX
17 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/s0DpcYpC0d
@MSRResearchTX
17 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Rapid7'nin AI Ajanının Bulduğu SharePoint Açığı Artık Gerçek Saldırılarda Kullanılıyor Daha önce duyurduğumuz ve Rapid7'nin AI ajanının bulduğu SharePoint kimlik doğrulama atlatma açığı CVE-2026-55040, yayınlanan PoC kodu sayesinde artık gerçek saldırg
@BTHaberler
17 Aug 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
攻撃者が、概念実証(PoC)公開後にSharePointの重大な脆弱性を悪用(CVE-2026-55040) Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) #HelpNetSecurity (Aug 13) https://t.co/OwAtZfZT9A
@foxbook
17 Aug 2026
242 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ثغرتان في شيربوينت تتشابكان لتحقيق استغلال كامل عن بُعد دون مصادقة. المعرّف : CVE-2026-63520 درجة الخطورة : 8.1 (CVSS) - High السلسلة مع : CVE-2026-55040 → Unauthenticated RCE الحل : Appl
@KasperskyDev
16 Aug 2026
296 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft SharePoint JWT token authentication bypass (CVE-2026-55040) and Windows Defender 0day vulnerability highlight the need for robust authentication and patching #ThreatIntel #CyberSecurity #CVE https://t.co/NOP2psjvvn
@Npj8448
15 Aug 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
"matchCriteriaId": "5FA63EA8-B225-4E35-A6A3-DBDECF5AC4C8",
"versionEndExcluding": "16.0.19725.20434",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F815EF1D-7B60-47BE-9AC2-2548F99F10E4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "6122D014-5BF1-4AF4-8B4D-80205ED7785E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]