A recently patched SharePoint vulnerability, CVE-2026-55040, is being actively exploited following the release of a proof-of-concept exploit. This vulnerability allows attackers to bypass authentication and potentially access or modify files without authorization. Security firm Rapid7 detailed the exploit on August 11, prompting concerns from CISA over the vulnerability's exploitation in the wild.
Microsoft released patches for CVE-2026-55040 during July Patch Tuesday, but detailed acknowledgment of its exploitation has lagged in Microsoft’s advisories. Additionally, another vulnerability, CVE-2026-63520, may be chained with it for remote code execution. Organizations are urged by CISA to update their systems immediately to mitigate risk.