SharePoint Vulnerability Exploited After Patch Release
A SharePoint vulnerability that was patched last month is being exploited in the wild, according to reports. The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates.
The issue allows an attacker to bypass a security feature over a network and could potentially allow them to disclose files and modify data. Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it.
Threat intelligence firm Defused reported that its honeypots have recorded exploitation attempts targeting CVE-2026-55040, and the attacks are leveraging the PoC released by Rapid7. Microsoft's advisory still does not mention exploitation, but it is not uncommon for the tech giant to only update its advisories days after attacks have been confirmed.