← back
CVE-2026-55040criticalunder attackCWE-1390

Microsoft SharePoint Server Security Feature Bypass Vulnerability

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.1epss 40%
from disclosure to weapon14 days
Published on NVDJul 14
1st PoC+14d
CISA KEV+35d
exploitation probability
40%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
8 public exploit(s)
Action required by CISAfederal deadline: 2026-08-21

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

Microsoft SharePoint has a weak authentication flaw that lets attackers bypass security protections remotely. This means unauthorized people could gain access to protected data and features without proper verification.

Technical detail

A weak authentication mechanism in Microsoft Office SharePoint allows network-based attackers to circumvent security controls without valid credentials. The vulnerability enables unauthorized access to restricted resources and functionality, requiring only network connectivity to the affected SharePoint instance.

Summary generated and translated by AI from the official description.
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.