CVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- CISA KEV-listed (remediation due 2026-08-21)
- EPSS 39.7% (98.5% percentile)
- CVSS 9.1 critical
Related briefings
- SharePoint exploit goes public with two attack paths 2026-08-24
- Hackers exploit critical VMware vCenter and Windows bugs 2026-08-18
- Hackers now attack a SharePoint flaw that skips the login 2026-08-17
- Microsoft fixes 421 flaws as new Defender zero-day drops 2026-08-12
- AI helped find SharePoint bugs behind a server takeover 2026-08-11