Jessica Entwistle
August 13 2026
Threat actors have begun exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint, following the public release of proof-of-concept exploit code. SecurityWeek reports that the vulnerability, which carries a CVSS score of 9.1, stems from weak authentication mechanisms and was patched by Microsoft in its July 2026 Patch Tuesday updates. Exploitation activity began shortly after the proof-of-concept was made publicly available, allowing attackers to bypass authentication and potentially gain unauthorised access to SharePoint environments. CISA had previously warned that the vulnerability could be exploited in the wild.
This pattern of rapid exploitation following proof-of-concept publication is increasingly common and creates a compressed window for organisations to apply patches before attacks begin. SharePoint is widely deployed across UK businesses for document management, collaboration and intranet services, often holding sensitive business information, customer data and operational documentation. The authentication bypass nature of the vulnerability means that exploitation does not require existing access or user interaction, making it particularly attractive to opportunistic attackers scanning for unpatched systems. For organisations that have not yet applied July 2026 patches, the risk of exploitation is immediate and material. The speed with which proof-of-concept code translates into active exploitation underscores the importance of timely patch management and the operational challenges of maintaining security across complex SharePoint deployments, including on-premises, hybrid and cloud configurations.
For UK businesses running SharePoint, this is a prompt to confirm that July 2026 patches have been applied across all SharePoint environments, including on-premises deployments and hybrid configurations. Review whether patch management processes are able to respond quickly when proof-of-concept code is published for critical vulnerabilities, and consider whether the organisation has visibility of all SharePoint instances, including development, test and legacy environments that may not be included in regular patching cycles. Review whether SharePoint access logs and authentication monitoring would detect unusual access patterns or bypass attempts, and ensure that incident response plans account for scenarios where authentication controls may have been bypassed. Consider whether vulnerability management processes prioritise patches based on exploitability and public proof-of-concept availability, not just CVSS scores.
Source: SecurityWeek