PoC release followed by immediate attacks on SharePoint bug
A SharePoint flaw patched by Microsoft (CVE-2026-55040) is being exploited after Rapid7 published a proof-of-concept on Aug. 11; honeypots recorded attacks on Aug. 12.
Rapid7 published technical details and a proof-of-concept exploit for CVE-2026-55040 on Aug. 11. The next day, threat intelligence firm Defused recorded attempted exploitations against honeypots using the publicly available PoC. Microsoft issued a patch for the vulnerability in its July Patch Tuesday updates.
Microsoft’s advisory described CVE-2026-55040 as a weak authentication issue that can be exploited over a network. The advisory warned, “Exploiting this vulnerability could allow an attacker to disclose files and modify data,” and added that “in a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection.”
Rapid7’s disclosure showed how a remote, unauthenticated actor could bypass SharePoint authentication and perform actions with the privileges of a site user or administrator. Rapid7 published a PoC script demonstrating the method.
Defused’s telemetry indicated exploitation attempts began on Aug. 12 and were leveraging the Rapid7 PoC. Microsoft has not updated its advisory to explicitly note active exploitation; the company has previously revised advisories after attacks were confirmed.
Rapid7 reported discovery of CVE-2026-63520, a separate SharePoint flaw addressed in Microsoft’s August Patch Tuesday updates, and noted it could be chained with CVE-2026-55040 to achieve unauthenticated remote code execution on affected servers. There are no public signs that CVE-2026-63520 is being used in attacks.
The U.S. Cybersecurity and Infrastructure Security Agency urged organizations to ensure SharePoint installations are up to date. CISA warned that CVE-2026-55040 could be exploited in the wild and has not yet added the vulnerability to its Known Exploited Vulnerabilities catalog.
CVE-2026-55040 is the fifth SharePoint vulnerability reported as exploited this summer, following CVE-2026-50522, CVE-2026-58644, CVE-2026-56164 and CVE-2026-45659. There is no public information identifying the actors behind these exploitation attempts.
Security firms and agencies recommend organizations verify patch status for SharePoint servers and apply Microsoft’s updates to reduce risk.








