CISA KEV Alert 8/18/2026, 7:43:22 PM

CISA flags critical SharePoint auth bypass CVE-2026-55040 in KEV

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE-2026-55040 to its Known Exploited Vulnerabilities catalogue, affecting Microsoft SharePoint. The entry covers the Microsoft SharePoint Weak Authentication Vulnerability, which allows an unauthenticated attacker to bypass a security feature over a network.

The vulnerability is an authentication bypass flaw that can be exploited remotely, potentially granting unauthorised access to SharePoint environments. It carries a CVSS v3.1 score of 9.1, rated CRITICAL, and a patch is available from Microsoft via the MSRC update guide.

Active exploitation has been confirmed, which is the basis for the KEV inclusion; there is no publicly known ransomware campaign linked to this CVE at present. CISA has set a remediation deadline of 26 August 2026 for affected federal agencies.

CISA requires Federal Civilian Executive Branch (FCEB) agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26‑04 Prioritizing Security Updates Based on Risk and the Forensics Triage Requirements. Agencies must follow BOD 26‑04 guidance for cloud services or discontinue use if mitigations are unavailable, and they are responsible for evaluating each asset's internet exposure and adhering to BOD 26‑04 patching guidelines. All organisations should review their SharePoint exposure and apply the available patch or vendor‑recommended mitigations.

For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-55040 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline