CVE-2026-55040
published 2026-07-14CVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.67%
47.8th percentile
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5561.1001 | 16.0.5561.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20175 | 16.0.10417.20175 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19725.20434 | 16.0.19725.20434 |
| microsoft | sharepoint_server | < 16.0.19725.20434 | 16.0.19725.20434 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-55040 is exploitable by a remote unauthenticated attacker who can bypass SharePoint JWT token validation; detect anomalous unauthenticated requests to SharePoint endpoints that return authenticated-level responses or perform privileged operations. ↗
- →Attackers may perform SID enumeration against Active Directory prior to exploiting CVE-2026-55040 to identify target user accounts; monitor for unusual SID enumeration activity against AD from external or unauthenticated sources. ↗
- →CVE-2026-55040 can be chained with an additional RCE vulnerability; monitor for post-authentication exploitation activity on SharePoint servers following unauthenticated access, including deserialization attempts and IIS machine key theft. ↗
- →Internet-facing SharePoint servers are the primary attack surface; prioritize monitoring and patching of on-premises SharePoint Server (Subscription Edition, 2019, and 2016) instances exposed to the internet. ↗
- ·Full technical details for CVE-2026-55040, including PoC, are withheld for up to 30 days from July 14, 2026 disclosure; detection opportunities based on technical specifics of the JWT bypass are limited until those details are published. ↗
- ·The RCE component of the exploit chain chained with CVE-2026-55040 is not yet patched as of July 14, 2026; patching CVE-2026-55040 alone breaks the full unauthenticated RCE chain but the RCE component patch is expected in August 2026. ↗
- ·Vulnerability checks in Rapid7 Exposure Command, InsightVM, and Nexpose are authenticated checks only, not unauthenticated; unauthenticated detection coverage may be limited. ↗
- ·All supported on-premises SharePoint Server versions are affected (Subscription Edition, 2019, and 2016); SharePoint Online/cloud-hosted instances may have different exposure. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Hackernews
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
blogs_hackernews·2026-07-15
CVE-2026-56164 Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse ) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.
"The PoC requires another standard user credential and a third username (which can be an administrator account)," Chaotic Eclipse said . "If the PoC is successful, it will e
Hackernews
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
blogs_hackernews·2026-07-15·CVSS 7.8
CVE-2026-56164 [HIGH] Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200 .
Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Serv
Rapid7
Patch Tuesday - July 2026
blogs_rapid7·2026-07-14·CVSS 9.6
CVE-2026-58617 [CRITICAL] Patch Tuesday - July 2026
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only ser
Talos
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-07-14·CVSS 8.8
CVE-2026-56155 [HIGH] Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical".
Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.
CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally.
CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit i
Sans Isc
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
blogs_sans_isc·2026-07-14·CVSS 6.1
CVE-2026-56155 [MEDIUM] Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
Published: 2026-07-14. Last Updated: 2026-07-14 19:14:58 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
Given the large number of vulnerabilities, it is difficult to point out "noteworthy" issues.
Already exploited vulnerabilities:
CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability. Micr
Qualys
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
blogs_qualys·2026-07-14
CVE-2026-50661 Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forJuly2026
Adobe Patch for July 2026
Zero-day Vulnerabilities Patched inJulyPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inJulyPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes, highlights the most critical vulnerabilities, and offers guidanc
Rapid7
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
blogs_rapid7·2026-07-14·CVSS 9.1
CVE-2026-55040 [CRITICAL] CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
## Overview
Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the first vulnerability in this chain, the authentication bypass vulnerability CVE-2026-55040. The RCE component of the exploit chain is expected to be patched by Microsoft in the next update cycle for August 2026. The exploit chain was developed as an entry for the recent Pwn2Own Berlin hacking competition – part of Rapid7 Labs' continued effort to raise the bar in Vulnerability Intelligence and our commitment to the preemptive protection of our customers through original vulner
Crowdstrike
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
blogs_crowdstrike
CVE-2026-56155 July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&
2026-07-14
Published