SharePoint Flaw Exploited by Attackers Despite July Patch
Microsoft's SharePoint has been hit by a critical vulnerability that is already being exploited by attackers. The flaw, tracked as CVE-2026-55040, was patched in July 2026 as part of Microsoft's Patch Tuesday updates.
Rapid7 researcher Stephen Fewer released an in-depth technical analysis of the flaw along with proof-of-concept exploit code, allowing threat actors to bypass authentication on a vulnerable SharePoint server and perform operations as a site user or administrator. 'A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator,' Fewer explained.
Defused warned that attackers are using the Rapid7 POC for CVE-2026-55040 against its SharePoint honeypots. Microsoft has yet to confirm if the bug has been exploited in the wild, but flags the flaw as a likely target when paired with another vulnerability, CVE-2026-63520.