CVE-2026-55040
CVE-2026-55040 is a critical-severity vulnerability in Microsoft Sharepoint Server with a CVSS 3.x base score of 9.1. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-08-18). The underlying weakness is classified as CWE-1390.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 5% (92nd percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2026-08-18)
- Weakness: CWE-1390
- Affected product: Microsoft Sharepoint Server
- Published:
- Last modified:
Description
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Frequently asked questions
- What is CVE-2026-55040?
- Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- How severe is CVE-2026-55040?
- CVE-2026-55040 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-55040 being actively exploited?
- Yes. CVE-2026-55040 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-08-18, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2026-55040?
- CVE-2026-55040 primarily affects Microsoft Sharepoint Server. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-55040?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- When was CVE-2026-55040 published?
- CVE-2026-55040 was published on 2026-07-14 and last updated on 2026-08-19.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
- https://github.com/sfewer-r7/CVE-2026-55040
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040
- https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
Affected products (3)
- cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Sharepoint Server
- CVE-2013-1330 — Critical (CVSS 10.0): The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and…
- CVE-2020-1595 — Critical (CVSS 9.9): <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from…
- CVE-2020-1210 — Critical (CVSS 9.9): <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source…
- CVE-2026-58644 — Critical (CVSS 9.8): Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a…
- CVE-2026-50522 — Critical (CVSS 9.8): Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a…
- CVE-2026-20963 — Critical (CVSS 9.8): Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a…
All CVEs affecting Microsoft Sharepoint Server →
Other CWE-1390 vulnerabilities
- CVE-2025-30412 — Critical (CVSS 10.0): Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis…
- CVE-2025-30411 — Critical (CVSS 10.0): Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis…
- CVE-2026-68067 — Critical (CVSS 9.8): The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live…
- CVE-2026-6886 — Critical (CVSS 9.8): Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass…
- CVE-2026-28710 — Critical (CVSS 9.8): Sensitive information disclosure and manipulation due to improper authentication. The following products are affected:…
- CVE-2025-40554 — Critical (CVSS 9.8): SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited,…