CVE-2026-55040 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-55040 | CVSS 9.1 (Critical) | Exploit: PoC available
What Is It
CVE-2026-55040 is a weak-authentication vulnerability in Microsoft SharePoint Server that allows an unauthorized network-based attacker to bypass a security feature.
Technical Detail
The vulnerability results from weak authentication handling in SharePoint Server. An attacker able to reach a vulnerable SharePoint Server over the network may be able to bypass an intended security control without valid authorization. The available description does not specify the affected SharePoint component, authentication flow, post-bypass privileges, or whether exploitation can lead to code execution.
Exploitation Status
A proof-of-concept exploit is available. There is no indication in the provided data that CISA has added this vulnerability to the Known Exploited Vulnerabilities catalog or confirmed active exploitation in the wild.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize deployment of Microsoft security updates for affected SharePoint Server installations as they become available, particularly for internet-accessible or externally reachable servers. Restrict network access to SharePoint administration and authentication endpoints to trusted users and networks, enforce strong authentication controls where supported, and review SharePoint and web-server logs for anomalous unauthenticated requests, unexpected authentication outcomes, and access to protected resources. No vendor workaround or specific detection indicator is confirmed in the available data.