SharePoint Vulnerability Exploited Shortly After PoC Release

https://www.securityweek.com/wp-content/uploads/2026/07/SharePoint.jpeg

A SharePoint vulnerability patched last month is now being exploited in the wild, with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit.

The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates.

Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network.

“Exploiting this vulnerability could allow an attacker to disclose files and modify data,” Microsoft said, adding, “In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection.”

Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it to bypass authentication and perform operations as a SharePoint site user or administrator. The security firm also made a PoC script available.

Threat intelligence firm Defused reported on August 12 that its honeypots have recorded exploitation attemptstargeting CVE-2026-55040...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more