CVE Tools

SharePoint Vulnerability Exploited Shortly After PoC Release

SecurityWeekBy Eduard Kovacs

Reported exploitedSharePoint

Our summary

Active exploitation has been observed for CVE-2026-55040, a weak authentication vulnerability in Microsoft SharePoint that was patched during July Patch Tuesday. The attacks began immediately following the publication of a proof-of-concept exploit by Rapid7, allowing unauthenticated remote attackers to bypass security controls and access sensitive data. This incident marks the fifth SharePoint flaw targeted this summer, prompting urgent patching recommendations from CISA.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store