- Sources: primary, advisory, report, discussion
- Summary: NVD carries CVE-2026-55040 from the
secure@microsoft.com CNA at CVSS 3.1 9.1 Critical under CWE-1390, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, so exploitation needs no credentials and no user interaction over the network, with high confidentiality and integrity impact and none to availability. The record was published 2026-07-14 and last modified 2026-08-13, it names the fixed builds as SharePoint Enterprise Server 2016 at 16.0.5561.1001, SharePoint Server 2019 at 16.0.10417.20175, and SharePoint Server Subscription Edition at 16.0.19725.20434, and its CISA SSVC entry scores exploitation as poc, automatable as yes, and technical impact as total. BleepingComputer reports that Rapid7 published proof-of-concept exploit code on 2026-08-11 in a write-up it credits to Stephen Fewer, and that threat intelligence firm Defused observed that code used against its SharePoint honeypots the next day, an observation that is Defused's own and that Microsoft has not matched with an exploited-in-the-wild flag. - Why it matters: Public exploit code now exists for an unauthenticated network bypass on a server class that sits inside corporate perimeters holding documents, the patch has been available since the July 2026 Patch Tuesday, and the named build numbers turn the response into a version comparison rather than a triage exercise.
- Follow-up: Track whether Microsoft flags the CVE as exploited in the wild and whether CISA adds it to the Known Exploited Vulnerabilities catalog.
send feedback on this story