Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3955 articles · 205830 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-55040KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft sharepoint server subscription editionmitre_affected90%
microsoftmicrosoft sharepointmitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040(vendor-advisory, patch)

Related News (26 articles)

Tier D
The Hacker News2d ago
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
→ No new info (linked only)
Tier D
BleepingComputer3d ago
Hackers target Microsoft SharePoint RCE chain with PoC exploit
→ No new info (linked only)
Tier C
Rapid7 Blog5d ago
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
→ No new info (linked only)
Tier D
SecurityWeek10d ago
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security10d ago
Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS
→ No new info (linked only)
Tier B
CERT-FR12d ago
Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)
→ No new info (linked only)
Tier D
Help Net Security16d ago
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
→ No new info (linked only)
Tier D
The Hacker News16d ago
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
→ No new info (linked only)
Tier D
SecurityWeek17d ago
SharePoint Vulnerability Exploited Shortly After PoC Release
→ No new info (linked only)
Tier C
Rapid7 Blog17d ago
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
→ No new info (linked only)
Tier D
BleepingComputer17d ago
Hackers leverage new Microsoft SharePoint exploit in attacks
→ No new info (linked only)
Tier C
Rapid7 Blog17d ago
Patch Tuesday - August 2026
→ No new info (linked only)
Tier D
The Hacker News18d ago
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
→ No new info (linked only)
Tier C
Rapid7 Blog18d ago
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
→ No new info (linked only)
Tier C
Rapid7 Blog18d ago
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
→ No new info (linked only)
Tier D
SecurityWeek43d ago
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
→ No new info (linked only)
Tier B
CCCS Canada44d ago
AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644
→ No new info (linked only)
Tier D
The Record45d ago
Microsoft smashes Patch Tuesday record for second successive month
→ No new info (linked only)
Tier D
The Hacker News45d ago
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
Rapid7 Blog45d ago
Patch Tuesday - July 2026
→ No new info (linked only)
Tier C
VulDB45d ago
CVE-2026-55040 | Microsoft SharePoint Server improper authorization
→ No new info (linked only)
Tier C
Qualys Blog45d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
Tier D
The Hacker News45d ago
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
→ No new info (linked only)
Tier A
Microsoft MSRC46d ago
CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog46d ago
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5561.1001
CWECWE-1390
PublishedJul 14, 2026
Last enriched44d agov7
Tags
zero-dayprivilege escalationremote code executionmissing authenticationdeserialization
Trending Score127🔥
Source articles26
Independent13
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 102
CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 59
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 51
HIGHCVE-2026-62911
Microsoft Exchange Server Elevation of Privilege Vulnerability
Trending: 44
HIGHCVE-2026-69414
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 40

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, exploitAvailable, activelyExploited
Jul 14, 2026
Updated: cweIds
Jul 14, 2026
Updated: description, affectedVersions, patchAvailable
Jul 14, 2026
Updated: affectedVersions, cweIds, tags
Jul 15, 2026
Updated: tags
Jul 15, 2026
Updated: affectedVersions, cweIds, tags
Jul 15, 2026
Actively Exploited
Aug 24, 2026
Exploit Available
Aug 24, 2026
Patch Available
Aug 24, 2026

Version History

v7
Last enriched 44d ago
v7Tier B44d ago

Updated affected versions, added new CWEs, and included new tags related to missing authentication and deserialization.

affectedVersionscweIdstags
via CCCS Canada
v6Tier D45d ago

Added CWE-20 and updated tags to include 'remote code execution'.

tags
via The Hacker News
v5Tier D45d ago

Added affected versions including Subscription Edition, 2019, and 2016, and new CWE and tags related to zero-day and privilege escalation.

affectedVersionscweIdstags
via The Hacker News
v4Tier C45d ago

Updated description with new technical details, added affected version, and specified the fixed version number.

descriptionaffectedVersionspatchAvailable
via Rapid7 Blog
v3Tier C45d ago

Updated description with new details, changed product to 'Microsoft SharePoint Server', severity to 'HIGH', and noted no exploit available.

cweIds
via VulDB
v2Tier A45d ago

Updated description with details about weak authentication and marked the vulnerability as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v145d ago

Initial creation