SharePoint Vulnerability Exploited Shortly After PoC Release

A recently patched SharePoint vulnerability is being actively exploited by attackers, just weeks after a proof-of-concept (PoC) exploit was released. The weakness, tracked as CVE-2026-55040, allows an unauthenticated attacker to bypass security features and gain access to sensitive data on vulnerable servers.

Microsoft had already addressed the issue with its July Patch Tuesday updates, describing it as a weak authentication vulnerability that enables attackers to disclose files and modify data on SharePoint sites. However, it seems that the company’s warning came too late for some organizations. Threat intelligence firm Defuse reported on August 12 that its honeypots have detected exploitation attempts targeting CVE-2026-55040, with the attacks using the PoC exploit made available by Rapid7.

The rapid escalation from a released PoC to actual exploitation highlights the urgent need for organizations to stay up-to-date with security patches. While Microsoft’s advisory on the vulnerability still doesn’t mention exploitation, it’s not uncommon for tech giants like Microsoft to only update their advisories after attacks have been confirmed. In this case, it appears that attackers were quick to pounce on the weakness once the PoC exploit was released.

The situation is further complicated by a related vulnerability, CVE-2026-63520, which Rapid7 discovered and reported on Tuesday. This flaw can be chained with CVE-2026-55040 to achieve unauthenticated remote code execution on vulnerable servers. Microsoft addressed CVE-2026-63520 in its August Patch Tuesday updates, but it’s unclear if it’s being exploited by attackers.

The exploitation of SharePoint vulnerabilities has become a growing concern for organizations this summer. The Cybersecurity and Infrastructure Security Agency (CISA) recently urged organizations to ensure their SharePoint instances are up-to-date and protected in light of the new wave of attacks. This warning came after CISA had previously warned that CVE-2026-55040 could be exploited in the wild.

The lack of public information on who is behind the exploitation of these weaknesses raises concerns about the sophistication and scope of the attacks. While there are no indications that a single group or nation-state actor is responsible for the exploitation, it’s clear that attackers are actively targeting SharePoint vulnerabilities to gain access to sensitive data.

In light of this new development, organizations should take immediate action to ensure their SharePoint instances are patched and up-to-date. This includes applying the latest security patches, reviewing access controls, and monitoring system logs for suspicious activity. By taking these proactive steps, organizations can reduce their risk exposure and prevent attackers from exploiting vulnerabilities like CVE-2026-55040.


Source: SecurityWeek — 2026-08-12