Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting a critical SharePoint authentication bypass vulnerability (CVE-2026-55040, CVSS 9.1) after a public proof-of-concept code was released, despite Microsoft having patched it in its July 2026 updates.

Threat actors are actively exploiting a critical Microsoft SharePoint authentication bypass vulnerability, CVE-2026-55040 (CVSS 9.1), after a proof-of-concept code was publicly released. The flaw stems from weak authentication, allowing attackers to bypass security features. Microsoft patched the issue in its July 2026 Patch Tuesday updates.