Security1 distinct publisher3 min readUpdated
CVE-2026-55040 was patched in July. Rapid7 published the technical details and a script on August 11, and Defused says its honeypots logged exploitation on August 12.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CVE-2026-55040 was patched in July. Rapid7 published the technical details and a script on August 11, and Defused says its honeypots logged exploitation on August 12.
Follow any of these and your For You feed starts watching them — no settings page required.
A SharePoint authentication bypass that Microsoft fixed in its July Patch Tuesday updates is now being exploited in the wild, with attacks beginning shortly after a proof-of-concept exploit was published [1][2]. The gap between public exploit code and observed attacks was one day, which is the operational number that matters for anyone still carrying the July patch as a scheduled item [4][5][11].
Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, describing how a remote, unauthenticated attacker could bypass authentication and perform operations as a SharePoint site user or administrator, and it released a PoC script alongside the writeup [4]. On August 12, threat intelligence firm Defused reported that its honeypots had recorded exploitation attempts against the flaw, and said the attacks were using Rapid7's PoC [5]. That is not adaptation or reverse engineering. That is copy and run.
Microsoft's own description was already sufficient to justify emergency handling. The company characterised CVE-2026-55040 as a weak authentication issue allowing a security feature bypass over a network [3]. "Exploiting this vulnerability could allow an attacker to disclose files and modify data," Microsoft said, adding that "in a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection" [3]. Unauthenticated, network-reachable, read and write. The advisory still does not mention exploitation, though delays of several days between confirmed attacks and an updated Microsoft advisory are routine [6].
The chaining risk raises the ceiling. Rapid7 also reported CVE-2026-63520, a separate SharePoint flaw that can be combined with CVE-2026-55040 to achieve unauthenticated remote code execution on servers [7]. Microsoft addressed CVE-2026-63520 in its August Patch Tuesday updates, and there is no indication it is being exploited [8]. For unpatched estates, that means the August cycle is not a separate maintenance question from the July one: the two together move the outcome from file disclosure and data modification to code execution.
CISA had already flagged this. The agency recently urged organisations to ensure SharePoint instances were up to date and protected in light of a new wave of attacks, and warned at the time that CVE-2026-55040 could be exploited in the wild [9]. It has not yet added the flaw to the KEV catalogue, which already lists more than a dozen SharePoint bugs [10]. Federal remediation clocks therefore have not started, even though the exploitation is confirmed by a third party.
Context on volume: CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has surfaced this summer, following CVE-2026-50522, CVE-2026-58644, CVE-2026-56164 and CVE-2026-45659 [12]. There is no public information on who is behind any of that activity [13]. Also worth noting for capacity planning: August Patch Tuesday carried 421 CVEs including one exploited zero-day [14].
Watch for a KEV addition for CVE-2026-55040 and for Microsoft to revise the advisory's exploitation status [6][10]. Watch for the chained CVE-2026-63520 path to appear in honeypot data, which would be the shift from data theft to server compromise [7][8]. And watch how long the deferred July patch survives as a deferral once attribution to a named actor appears [13].
Ranked by verification strength, evidence, and original report placement.
A SharePoint vulnerability patched last month is now being exploited in the wild, with attacks starting shortly after the release of a proof-of-concept exploit.
The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates.
Microsoft described CVE-2026-55040 as a weak authentication issue that allows an attacker to bypass a security feature over a network, saying "Exploiting this vulnerability could allow an attacker to disclose files and modify data" and "In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection."
Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it to bypass authentication and perform operations as a SharePoint site user or administrator, and made a PoC script available.
Threat intelligence firm Defused reported on August 12 that its honeypots had recorded exploitation attempts targeting CVE-2026-55040, and that the attacks were leveraging the PoC released by Rapid7.
Microsoft's advisory still does not mention exploitation, and it is not uncommon for the company to update its advisories only days after attacks have been confirmed.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named-vendor sourcing, no independent or authority confirmation
Every load-bearing fact is attributed to an identifiable party (Microsoft advisory text, Rapid7 disclosure and PoC, Defused honeypot telemetry, CISA guidance), which is better than anonymous sourcing. But the cluster has one publisher and no second observer of the exploitation, and the two authorities that would normally confirm it, Microsoft's advisory and CISA's KEV catalog, explicitly have not. Honeypot hits also evidence attack traffic rather than successful compromise.
Exploitation observed but unquantified; exposure unknown
There is concrete real-world activity: a public PoC on August 11 and honeypot-recorded exploitation attempts on August 12, set against a summer pattern of five SharePoint flaws under exploitation and a dozen-plus SharePoint entries in KEV. What is missing is any magnitude: no attempt counts, no targeted sectors or geographies, no confirmed victims, and no figures on vulnerable or unpatched SharePoint instances, so operational reach cannot be scored higher.
Slightly overstated: honeypot traffic framed as exploitation in the wild
The headline framing (PoC to honeypot hits in a day, advisory still silent) is accurate to the dated record and the article itself notes that advisory lag is routine and that attribution is unknown, which restrains the framing. The modest positive gap comes from treating single-vendor honeypot attempts as established in-the-wild exploitation without volume, victim, or KEV confirmation, and from the RCE-chain detail sitting next to exploitation news even though CVE-2026-63520 shows no exploitation.
Vendor research and threat-intel promotion drive the record
The disclosure chain is commercially interested: Rapid7 both found the flaws and published a working PoC, which advertises its research capability while accelerating attacker tooling, and Defused's honeypot report showcases its telemetry product. Microsoft has a reputational incentive not to annotate an advisory as exploited, and the article notes it typically updates only days later. CISA's incentive is defensive urgency. None of these parties is disinterested, though their claims are on the record and named.
Dated facts are solid; scope and impact are not
Confidence is moderate: the timeline, patch attribution, advisory status and KEV absence are checkable and internally consistent, and the article is careful about what is unknown. It is limited by one publisher, one telemetry source for the exploitation itself, no independent verification, and no data on exposure or successful compromise, so conclusions about severity of real-world impact remain provisional.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
leadership
Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem1 distinct publisher
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 12, 2026