Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA orders SharePoint hardening against CVE-2026-55040

Public Sector Action
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

CISA ordered federal agencies and network defenders on August 18, 2026 to secure SharePoint servers against ongoing CVE-2026-55040 attacks. The directive increases pressure on organizations running exposed SharePoint deployments that face active exploitation attempts. It adds federal urgency to hardening steps for systems that could be used as entry points for follow-on compromise.

Related Happenings

CISA adds CVE-2026-68820 to KEV catalog

Public Sector Action
H score3 First: 12.08.2026 09:41 Last: 12.08.2026 09:41 Sources 1

About this happening: CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by August 25, 2026. The action formal...

SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
H score45 First: 11.08.2026 19:47 Last: 11.08.2026 19:47 Sources 1

How related: "The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server."

About this happening: CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an admini...

Latest development: 26.08.2026 17:47

Rapid7 security researcher Stephen Fewer releases a proof-of-concept exploit for CVE-2026-55040, the SharePoint authentication bypass in the JWT token validation pipeline that can let attackers perform operations as a site user or administrator.

CISA publishes OSS security guide for federal agencies

Public Sector Action
H score25 First: 30.07.2026 15:00 Last: 30.07.2026 15:00 Sources 1

About this happening: CISA published Open Source Software: Security Principles and Practices for federal agencies on July 30, 2026, giving them guidance for using, assessing, contributi...

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action
H score37 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...

CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw

Public Sector Action
H score36 First: 16.06.2026 13:47 Last: 16.06.2026 13:47 Sources 1

About this happening: CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under ...

Timeline

  1. 26.08.2026 17:47 1 articles · 2h ago

    Rapid7 SharePoint exploit code is weaponized in attacks

    Technical Analysis Update

    One day after the public proof-of-concept for CVE-2026-55040 appeared, Defused said Rapid7's exploit code had already been weaponized in attacks against unpatched Microsoft SharePoint servers.

    Show sources
  2. 26.08.2026 17:47 2 articles · 2h ago

    CISA orders SharePoint servers secured against ongoing CVE-2026-55040 attacks

    Legal Policy Action Update

    On August 18, CISA ordered federal agencies and network defenders to secure SharePoint servers against ongoing CVE-2026-55040 attacks and urged teams to review Microsoft's SharePoint Server security-hardening guidance while avoiding direct internet exposure unless necessary.

    Show sources
  3. 26.08.2026 17:47 1 articles · 2h ago

    Defused sees CVE-2026-55040 and CVE-2026-63520 chaining in honeypots

    Exploitation Observed

    On August 25, Defused said threat actors were chaining the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain in its honeypots, with the JWT bypass exercised before heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520; no code execution was observed yet.

    Show sources