SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an administrator, on affected on-premises systems. Researchers also chained it to CVE-2026-63520 to reach code execution without credentials. SharePoint Server Subscription Edition, 2019, and 2016 are affected, while SharePoint Online is not listed, and the July update is said to break the chain.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score56
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
How related:
Likely based on Microsoft's exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationHow related: Likely based on Microsoft's exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.
About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score79
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
How related:
CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to light this summer, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveHow related: CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to light this summer, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.
About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
H score44
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Warlock ransomware post-exploitation tooling upgrades
Malware Activity
H score38
First: 17.03.2026 17:36
Last: 17.03.2026 17:36
Sources 1
About this happening:
The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Warlock ransomware post-exploitation tooling upgrades
Malware ActivityAbout this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Timeline
-
11.08.2026 19:47 4 articles · 14d ago
Rapid7 discloses AI-assisted SharePoint exploit chain reaching unauthenticated RCE
Initial DisclosureRapid7 disclosed an AI-assisted exploit chain against Microsoft SharePoint that uses CVE-2026-55040 to impersonate any user without a valid account and then chains CVE-2026-63520 to reach unauthenticated remote code execution on SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. The firm published its full technical analysis and a proof-of-concept script on August 11 after research sprints in January and March 2026.
Show sources
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE — thehackernews.com — 11.08.2026 19:47
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE — thehackernews.com — 11.08.2026 19:47
- Hackers leverage new Microsoft SharePoint exploit in attacks — www.bleepingcomputer.com — 12.08.2026 15:25
- SharePoint Vulnerability Exploited Shortly After PoC Release — www.securityweek.com — 12.08.2026 17:47
-
14.07.2026 03:00 1 articles · 1mo ago
Microsoft ships July SharePoint updates that break the exploit chain
Mitigation Patch UpdateMicrosoft shipped July updates for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, and Rapid7 says that update breaks the CVE-2026-55040 to CVE-2026-63520 chain. On July 14, CISA said the bypass was not yet known to have been exploited and filed an assessment marking the attack automatable with total technical impact.
Show sources
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE — thehackernews.com — 11.08.2026 19:47