LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on Aug 18, 2026, with a federal patch deadline of Aug 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-55040 is a weak authentication vulnerability in Microsoft SharePoint. According to CISA, it allows an unauthorized attacker to bypass a security feature over a network. For organizations that run SharePoint for collaboration, document storage, or intranet services, a bypass of authentication-related controls can undermine access boundaries and increase the risk of unauthorized use of those systems. Exact affected builds, configurations, and severity details are not provided here; confirm them against the vendor advisory before acting.

This guidance is for IT and security teams. Treat the issue as a network-reachable authentication weakness in the SharePoint product class, prioritize inventory and vendor-directed fixes, and align response with CISA’s direction to apply mitigations per vendor instructions and BOD 26-04 risk-based update practices.

How it works

The reported weakness is CWE-1390 (Weak Authentication). In plain terms, authentication is meant to establish that a requester is who or what it claims to be before sensitive features or data are available. A weak authentication design or implementation can let an unauthorized party satisfy or skip checks that should have blocked them.

CISA’s summary states that an unauthorized attacker can bypass a security feature over a network. That implies remote reachability to the vulnerable SharePoint surface without prior authorization, and abuse of the weak authentication behavior to get past a control that defenders would normally rely on. Public detail in the provided record does not describe packet-level mechanics, required endpoints, or proof-of-concept steps. Do not assume exploit preconditions beyond what the vendor and CISA publish; map attack paths only after reading the official advisory for this CVE.

In SharePoint environments, authentication and related security features often sit in front of site collections, APIs, admin interfaces, and integrated identity flows. A bypass in that layer can expand what an unauthenticated or improperly authenticated network attacker can attempt next. Ransomware use is not documented for this CVE in the facts given.

Am I affected? How to find it in your systems

SharePoint commonly appears as on-premises SharePoint Server farms, hybrid deployments, and related Microsoft collaboration stacks that your identity and web tiers front. Cloud-hosted Microsoft 365 SharePoint Online is a different operational model; still evaluate tenant configuration and any hybrid connectors against the vendor advisory, and follow BOD 26-04 guidance applicable to cloud services where relevant.

Practical inventory steps:

Telemetry and log clues are general for authentication-bypass classes until the vendor specifies indicators: repeated anonymous or unexpected access to authenticated resources; authentication success patterns that do not match normal identity provider logs; anomalous calls to SharePoint REST/_api or other management endpoints from unusual networks; sudden privilege or content access by accounts that should not have passed front-door controls. Correlate SharePoint ULS logs, IIS logs, reverse-proxy logs, and identity provider sign-in logs. Confirm any IoCs against the vendor advisory rather than inventing signatures.

How to remediate

Patch first. Apply the Microsoft update or mitigation package named for CVE-2026-55040 in the official vendor advisory, following your standard change process for SharePoint farms (test in staging, validate search and custom solutions, then roll forward). CISA’s required action is to apply mitigations in accordance with vendor instructions, ensure compliance with BOD 26-04 prioritizing security updates based on risk, and follow CISA’s forensics triage requirements as referenced in their notes. For cloud services, follow applicable BOD 26-04 guidance; if mitigations are unavailable, discontinue use of the product as directed in that guidance.

After installing the vendor fix:

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until the vendor fix is in place:

Reassess daily until patches are deployed; compensating controls are stopgaps only.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and broader incidents even when ransomware use is not documented for a specific CVE. If SharePoint content, identities, or connected systems may have been reached, follow your incident response plan: preserve logs, assess scope, reset affected credentials, and complete forensics triage in line with CISA guidance referenced for this action. You can also run a free exposure scan of your email addresses against known breach datasets to see whether those identities already appear in public breach collections, then prioritize monitoring and password hygiene for any hits.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-1390
Added to CISA KEVAug 18, 2026
Federal patch deadlineAug 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities