CVE detail
CVE-2026-55040
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 17
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
36 source links · newest first
ur new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerabilit
governmentwww.cisa.govAug 18, 2026, 12:00 PMluding international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited […]
newssecurityaffairs.comAug 16, 2026, 8:31 AM- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayHelp Net Security
f Salesforce and ServiceNow portals around the world. N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). Metabase zero-day exploited
newswww.helpnetsecurity.comAug 16, 2026, 8:00 AM vidence Points to Scraping | US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks | Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | SharePoint CVE-2026-55040 Comes Under Attack Follow
newssecurityaffairs.comAug 16, 2026, 7:24 AMvidence Points to Scraping | US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks | Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | SharePoint CVE-2026-55040 Comes Under Attack Follow
newssecurityaffairs.comAug 15, 2026, 5:48 PMvidence Points to Scraping | US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks | Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | SharePoint CVE-2026-55040 Comes Under Attack Follow
newssecurityaffairs.comAug 15, 2026, 5:48 PMvidence Points to Scraping | US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks | Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | SharePoint CVE-2026-55040 Comes Under Attack Follow
newssecurityaffairs.comAug 14, 2026, 8:43 AMting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates. “The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft
newswww.helpnetsecurity.comAug 13, 2026, 1:05 PMAttackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July
newssecurityaffairs.comAug 13, 2026, 8:36 AMosoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication
newsthehackernews.comAug 13, 2026, 6:09 AMvidence Points to Scraping | US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks | Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | SharePoint CVE-2026-55040 Comes Under Attack Follow
newssecurityaffairs.comAug 12, 2026, 8:05 PMMalware Mobile Reports Security Social Networks Terrorism ICS-SCADA Crypto POLICIES Contact me MUST READ Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | SharePoint CVE-2026-55040 Comes Under Attack Follow
newssecurityaffairs.comAug 12, 2026, 5:58 PMwith the attacks starting shortly after the release of a proof-of-concept (PoC) exploit. The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates. Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network. “Exploiting this vulnerability coul
newswww.securityweek.comAug 12, 2026, 2:47 PMktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft; this vulnerability is the se
vendorwww.rapid7.comAug 11, 2026, 9:10 PM- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCEThe Hacker News
with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's
newsthehackernews.comAug 11, 2026, 4:47 PM Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: The Rapid7 L
vendorwww.rapid7.comAug 11, 2026, 1:00 PMt server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to disclosure
vendorwww.rapid7.comAug 11, 2026, 1:00 PM- July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-DaysCrowdStrike
t families affected by July 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Active Directory Federation Services CVE-2026-56155 is an Important elevation of privilege vulnerability affecting Active Directory Federation Services (AD FS) and has a CVSS score of 7.8 . An insufficient granularity of access control flaw (CWE-1220) allows a low-privil
vendorwww.crowdstrike.comJul 17, 2026, 8:00 PM y remote code execution (RCE) vulnerability in Microsoft SharePoint, the US cybersecurity agency CISA warns. Tracked as CVE-2026-58644 (CVSS score of 9.8) and fixed as part of Microsoft’s July 2026 Patch Tuesday updates, the flaw is described as a deserialization of untrusted data issue. “In a network-based attack, an attacker authenticated as at least
newswww.securityweek.comJul 17, 2026, 7:15 AMs deployments. Key Takeaways CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence. Two additional SharePoint Server vulnerabilities disclosed
vendorwww.tenable.comJul 16, 2026, 4:00 PMosts Related blog posts Vulnerabilities and Exploits Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) Stephen Fewer Products and Tools What’s New in Rapid7 Products and Services: Q2 2026 in Review Ed Montgomery Vulnerabilities and Exploits CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED) Ste
vendorwww.rapid7.comJul 16, 2026, 1:00 PM- CISA sounds alarm over trio of exploited SharePoint flawsThe Register Security
upported version of SharePoint Server on-prem, with three vulnerabilities of particular interest cited. A spoofing bug, CVE-2026-32201 (6.5), was the first to be mentioned. Microsoft disclosed it in March and CISA confirmed it was being actively exploited in June. Additionally, CISA appears concerned by CVE-2026-45659 (8.8) – a remote code execution (R
newswww.theregister.comJul 15, 2026, 3:21 PM icrosoft shipped patches for a record 622 flaws , including two privilege escalation shortcomings in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8) that have been flagged as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both
newsthehackernews.comJul 15, 2026, 11:07 AM- CISA warns admins to patch actively exploited SharePoint flawsBleepingComputer
hree vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model)
newswww.bleepingcomputer.comJul 15, 2026, 9:44 AM ation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i
vendorwww.rapid7.comJul 14, 2026, 10:00 PMication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in July Patch Tuesday Edition CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability Insufficient granularity of access control in Active Directory Federation Services (AD FS) could allow an authenticated attacker to elevate priv
vendorblog.qualys.comJul 14, 2026, 9:23 PMed as "critical." Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileg
vendorblog.talosintelligence.comJul 14, 2026, 8:27 PMedits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Neither is one of the splashy remote code execution criticals. They are privilege bugs in two systems that matter more than th
newsthehackernews.comJul 14, 2026, 8:25 PMNo excerpt available.
Exploitwww.cisa.govJul 14, 2026, 6:18 PM- https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/www.rapid7.com
No excerpt available.
Exploitwww.rapid7.comJul 14, 2026, 6:18 PM No excerpt available.
Exploitgithub.comJul 14, 2026, 6:18 PMile no official fix is available. The two actively exploited zero-days addressed during this month's Patch Tuesday are: CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in Active Directory Federation Services that grants administrative privileges. "Insuf
newswww.bleepingcomputer.comJul 14, 2026, 6:01 PM- The July 2026 Security Update ReviewZero Day Initiative
oser look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild. - CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-contro
vendorwww.thezdi.comJul 14, 2026, 5:56 PM Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
vendormsrc.microsoft.comJul 14, 2026, 2:00 PMboth Rapid7 and Microsoft are disclosing the first vulnerability in this chain, the authentication bypass vulnerability CVE-2026-55040. The RCE component of the exploit chain is expected to be patched by Microsoft in the next update cycle for August 2026. The exploit chain was developed as an entry for the recent Pwn2Own Berlin hacking competition – pa
vendorwww.rapid7.comJul 14, 2026, 1:00 PMUpdate July 16, 2026 : CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , CVE-2026-56164 , and CVE-2026-58644 , enabling cyber threa
governmentwww.cisa.govJul 14, 2026, 12:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- sfewer-r7/CVE-2026-55040High confidencegithubNVD Exploit reference0 starsDiscovered Aug 18, 2026, 9:10 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-68067CVSS 9.3 · Critical
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email…
- CVE-2026-59135CVSS 5.5 · Medium
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
- CVE-2026-59554CVSS 7.5 · High
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
- CVE-2026-50756CVSS 7.5 · High
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
- CVE-2026-10714CVSS 8.8 · High
A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability ste…
- CVE-2026-57352CVSS 4.8 · Medium
Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.