Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-55040KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft sharepoint server subscription editionmitre_affected90%
microsoftmicrosoft sharepointmitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040(vendor-advisory, patch)

Related News (23 articles)

Tier D
SecurityWeek4d ago
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security5d ago
Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS
→ No new info (linked only)
Tier B
CERT-FR7d ago
Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)
→ No new info (linked only)
Tier D
Help Net Security10d ago
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
→ No new info (linked only)
Tier D
The Hacker News11d ago
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
→ No new info (linked only)
Tier D
SecurityWeek11d ago
SharePoint Vulnerability Exploited Shortly After PoC Release
→ No new info (linked only)
Tier C
Rapid7 Blog11d ago
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
→ No new info (linked only)
Tier D
BleepingComputer11d ago
Hackers leverage new Microsoft SharePoint exploit in attacks
→ No new info (linked only)
Tier C
Rapid7 Blog12d ago
Patch Tuesday - August 2026
→ No new info (linked only)
Tier D
The Hacker News12d ago
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
→ No new info (linked only)
Tier C
Rapid7 Blog12d ago
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
→ No new info (linked only)
Tier C
Rapid7 Blog12d ago
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
→ No new info (linked only)
Tier D
SecurityWeek37d ago
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
→ No new info (linked only)
Tier B
CCCS Canada39d ago
AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644
→ No new info (linked only)
Tier D
The Record39d ago
Microsoft smashes Patch Tuesday record for second successive month
→ No new info (linked only)
Tier D
The Hacker News39d ago
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
Rapid7 Blog40d ago
Patch Tuesday - July 2026
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-55040 | Microsoft SharePoint Server improper authorization
→ No new info (linked only)
Tier C
Qualys Blog40d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
Tier D
The Hacker News40d ago
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
→ No new info (linked only)
Tier A
Microsoft MSRC40d ago
CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog41d ago
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5561.1001
CWECWE-1390
PublishedJul 14, 2026
Last enriched39d agov7
Tags
zero-dayprivilege escalationremote code executionmissing authenticationdeserialization
Trending Score86
Source articles23
Independent13
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 128
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 79
HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 72
HIGHCVE-2026-45586EXPKEV
Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Trending: 64
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 59

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, exploitAvailable, activelyExploited
Jul 14, 2026
Updated: cweIds
Jul 14, 2026
Updated: description, affectedVersions, patchAvailable
Jul 14, 2026
Updated: affectedVersions, cweIds, tags
Jul 15, 2026
Updated: tags
Jul 15, 2026
Updated: affectedVersions, cweIds, tags
Jul 15, 2026
Actively Exploited
Aug 19, 2026
Exploit Available
Aug 19, 2026
Patch Available
Aug 19, 2026

Version History

v7
Last enriched 39d ago
v7Tier B39d ago

Updated affected versions, added new CWEs, and included new tags related to missing authentication and deserialization.

affectedVersionscweIdstags
via CCCS Canada
v6Tier D39d ago

Added CWE-20 and updated tags to include 'remote code execution'.

tags
via The Hacker News
v5Tier D39d ago

Added affected versions including Subscription Edition, 2019, and 2016, and new CWE and tags related to zero-day and privilege escalation.

affectedVersionscweIdstags
via The Hacker News
v4Tier C40d ago

Updated description with new technical details, added affected version, and specified the fixed version number.

descriptionaffectedVersionspatchAvailable
via Rapid7 Blog
v3Tier C40d ago

Updated description with new details, changed product to 'Microsoft SharePoint Server', severity to 'HIGH', and noted no exploit available.

cweIds
via VulDB
v2Tier A40d ago

Updated description with details about weak authentication and marked the vulnerability as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v140d ago

Initial creation