Find notable cyber news and cases, enriched with sources, timelines, and signals.

SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 45
3 unique sources, 3 articles

Summary

Hide ▲

CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an administrator, on affected on-premises systems. Researchers also chained it to CVE-2026-63520 to reach code execution without credentials. SharePoint Server Subscription Edition, 2019, and 2016 are affected, while SharePoint Online is not listed, and the July update is said to break the chain.

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score56 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

How related: Likely based on Microsoft's exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score79 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

How related: CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to light this summer, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Storm-1175 high-velocity zero-day and N-day intrusion campaign

Campaign
H score44 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...

Warlock ransomware post-exploitation tooling upgrades

Malware Activity
H score38 First: 17.03.2026 17:36 Last: 17.03.2026 17:36 Sources 1

About this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...

Timeline

  1. 11.08.2026 19:47 4 articles · 14d ago

    Rapid7 discloses AI-assisted SharePoint exploit chain reaching unauthenticated RCE

    Initial Disclosure

    Rapid7 disclosed an AI-assisted exploit chain against Microsoft SharePoint that uses CVE-2026-55040 to impersonate any user without a valid account and then chains CVE-2026-63520 to reach unauthenticated remote code execution on SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. The firm published its full technical analysis and a proof-of-concept script on August 11 after research sprints in January and March 2026.

    Show sources
  2. 14.07.2026 03:00 1 articles · 1mo ago

    Microsoft ships July SharePoint updates that break the exploit chain

    Mitigation Patch Update

    Microsoft shipped July updates for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, and Rapid7 says that update breaks the CVE-2026-55040 to CVE-2026-63520 chain. On July 14, CISA said the bypass was not yet known to have been exploited and filed an assessment marking the attack automatable with total technical impact.

    Show sources