Vulnerability
Published 2026-08-18
Verified 2026-09-19

Microsoft SharePoint weak authentication (CVE-2026-55040)

Weak authentication in on-premises Microsoft SharePoint (CVE-2026-55040) lets an unauthorised attacker bypass a security feature over the network. CISA added it to KEV on 18 August 2026 after evidence of active exploitation. NVD scores it 9.1 (CVSS 3.1). It is the auth-bypass half of an unauthenticated RCE chain with August's CVE-2026-63520 (Business Connectivity Services RCE). Apply the July/August SharePoint security updates for Subscription Edition, 2019 and 2016, and keep farms off the public internet unless required.

Product
Microsoft SharePoint Server
Versions
Supported on-prem SharePoint builds before the July 2026 security updates (see MSRC)
CVSS
(CVSS 3.1, NVD Critical)
Exploited in Australia?
unknown
Patch to
July 2026 SharePoint security updates (MSRC CVE-2026-55040); also apply August CVE-2026-63520 updates

Primary: Microsoft MSRC (CVE-2026-55040) · Vendor: Microsoft Security Update Guide · CVE: CVE-2026-55040, CVE-2026-63520 · CISA KEV addition notice (18 Aug 2026)

vulnerabilities