Who is affected
Microsoft SharePoint deployments are vulnerable to a weak authentication bypass that allows an attacker without valid credentials to circumvent a security feature over a network. The record does not specify which SharePoint versions or deployment models (on-premises, hybrid, or cloud-hosted) are affected, nor does it indicate whether all instances are equally exploitable or whether certain configurations are resistant.
How to check whether this touches you
- Inventory whether your organisation runs SharePoint in any form: on-premises, hybrid, or Office 365 cloud-hosted.
- Determine whether each SharePoint instance is reachable from the internet or from any untrusted network segment; consult your network boundary documentation and firewall rules.
- Gather the exact version and build number from each affected server using SharePoint Central Administration or cloud tenant settings; note that version numbers alone do not confirm exposure if backported security updates have been applied.
- Check Microsoft's security update guidance and your patch management records to confirm whether the remediation has been deployed.
What to do
- Immediately obtain the current Microsoft security advisory and patch guidance for CVE-2026-55040 from the Microsoft Security Update Guide and review it against your deployment topology.
- If you cannot patch within the CISA deadline of 2026-08-21, apply any available mitigations from Microsoft's guidance and document them in your risk register.
- Restrict network access to SharePoint endpoints to only authenticated, trusted clients; if the instance is cloud-hosted, review and enforce conditional access and multi-factor authentication policies to raise the cost of exploitation.
- Enable and review authentication and authorisation logs (user logon events, failed authentication attempts, and suspicious token usage) from the date this vulnerability was disclosed backwards.
- If your organisation operates under federal contract or receives federal funding, ensure compliance with CISA BOD 26-04 timelines and document your remediation steps.
If you find you were exposed
Exploitation of authentication bypasses typically occurs before public disclosure, so retrieve and examine authentication logs, session logs, and access tokens from at least the past 90 days. Check for accounts that logged in without a password, from unusual geographic locations, or at off-hours; also inspect file access and modification logs for unexpected changes to sensitive SharePoint content. Log retention limitations may prevent you from reaching back further, so prioritise the most recent 30 days for detail.