Apply the latest Microsoft security updates released as part of the July 2026 Patch Tuesday. Prioritize patching SharePoint servers to prevent exploitation of CVE-2026-55040. Monitor Microsoft security advisories for any additional guidance.
Quick answers
What is CVE-2026-55040?
Apply the latest Microsoft security updates released as part of the July 2026 Patch Tuesday. Prioritize patching SharePoint servers to prevent exploitation of CVE-2026-55040. Monitor Microsoft security advisories for any additional guidance.
How severe is CVE-2026-55040?
critical, CVSS 9.1
Is CVE-2026-55040 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-55040 be mitigated?
Apply the latest Microsoft security updates released as part of the July 2026 Patch Tuesday. Prioritize patching SharePoint servers to prevent exploitation of CVE-2026-55040. Monitor Microsoft security advisories for any additional guidance.
CVSS
9.1
Vendor
Microsoft
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
SharePoint
Mitigation
Apply the latest Microsoft security updates released as part of the July 2026 Patch Tuesday. Prioritize patching SharePoint servers to prevent exploitation of CVE-2026-55040. Monitor Microsoft security advisories for any additional guidance.
On August 18, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. The additions include a Microsoft IKE Service Extensions double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal, and an macOS improper authentication issue. CISA's Binding Operational Directive 26-04 reinforces rapid remediation requirements for Federal Civilian Executive Branch agencies on publicly exposed assets.
Threat actors have begun exploiting CVE-2026-55040, a critical security feature bypass vulnerability in Microsoft SharePoint, following the release of public proof-of-concept code. The flaw, which stems from weak authentication mechanisms, allows unauthenticated attackers to bypass security features. Microsoft released a patch as part of its July 2026 Patch Tuesday updates. The vulnerability carries a CVSS score of 9.1, indicating critical severity. Organizations using SharePoint are urged to apply the latest security updates immediately to mitigate the risk of active exploitation.