ZeroDayAlert

CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

Microsoft SharePoint Added to KEV 2026-08-18 Federal due 2026-08-21 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Microsoft SharePoint deployments are vulnerable to a weak authentication bypass that allows an attacker without valid credentials to circumvent a security feature over a network. The record does not specify which SharePoint versions or deployment models (on-premises, hybrid, or cloud-hosted) are affected, nor does it indicate whether all instances are equally exploitable or whether certain configurations are resistant.

How to check whether this touches you

  • Inventory whether your organisation runs SharePoint in any form: on-premises, hybrid, or Office 365 cloud-hosted.
  • Determine whether each SharePoint instance is reachable from the internet or from any untrusted network segment; consult your network boundary documentation and firewall rules.
  • Gather the exact version and build number from each affected server using SharePoint Central Administration or cloud tenant settings; note that version numbers alone do not confirm exposure if backported security updates have been applied.
  • Check Microsoft's security update guidance and your patch management records to confirm whether the remediation has been deployed.

What to do

  1. Immediately obtain the current Microsoft security advisory and patch guidance for CVE-2026-55040 from the Microsoft Security Update Guide and review it against your deployment topology.
  2. If you cannot patch within the CISA deadline of 2026-08-21, apply any available mitigations from Microsoft's guidance and document them in your risk register.
  3. Restrict network access to SharePoint endpoints to only authenticated, trusted clients; if the instance is cloud-hosted, review and enforce conditional access and multi-factor authentication policies to raise the cost of exploitation.
  4. Enable and review authentication and authorisation logs (user logon events, failed authentication attempts, and suspicious token usage) from the date this vulnerability was disclosed backwards.
  5. If your organisation operates under federal contract or receives federal funding, ensure compliance with CISA BOD 26-04 timelines and document your remediation steps.

If you find you were exposed

Exploitation of authentication bypasses typically occurs before public disclosure, so retrieve and examine authentication logs, session logs, and access tokens from at least the past 90 days. Check for accounts that logged in without a password, from unusual geographic locations, or at off-hours; also inspect file access and modification logs for unexpected changes to sensitive SharePoint content. Log retention limitations may prevent you from reaching back further, so prioritise the most recent 30 days for detail.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-55040 is being exploited. It cannot tell you whether SharePoint is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →