A SharePoint vulnerability patched last month is now being exploited in the wild, with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit.
The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates.
Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network.
“Exploiting this vulnerability could allow an attacker to disclose files and modify data,” Microsoft said, adding, “In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection.”
Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it to bypass authentication and perform operations as a SharePoint site user or administrator. The security firm also made a PoC script available.










