Skip to content

Security1 publisher3 min readPublished Updated

SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent

CVE-2026-55040 was patched in July. Rapid7 published the technical details and a script on August 11, and Defused says its honeypots logged exploitation on August 12.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent
Photo: thehackernews.com

What happened

  • A SharePoint vulnerability patched last month is now being exploited in the wild, with attacks starting shortly after the release of a proof-of-concept exploit.
  • The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates.
  • Microsoft described CVE-2026-55040 as a weak authentication issue that allows an attacker to bypass a security feature over a network, saying "Exploiting this vulnerability could allow an attacker to disclose files and modify data" and "In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection."
  • Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it to bypass authentication and perform operations as a SharePoint site user or administrator, and made a PoC script available.
  • Threat intelligence firm Defused reported on August 12 that its honeypots had recorded exploitation attempts targeting CVE-2026-55040, and that the attacks were leveraging the PoC released by Rapid7.

Compiled by The WatchSomething wrong?How this is made

Why it matters

A SharePoint authentication bypass that Microsoft fixed in its July Patch Tuesday updates is now being exploited in the wild, with attacks beginning shortly after a proof-of-concept exploit was published [1][2]. The gap between public exploit code and observed attacks was one day, which is the operational number that matters for anyone still carrying the July patch as a scheduled item [4][5][11].

Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, describing how a remote, unauthenticated attacker could bypass authentication and perform operations as a SharePoint site user or administrator, and it released a PoC script alongside the writeup [4]. On August 12, threat intelligence firm Defused reported that its honeypots had recorded exploitation attempts against the flaw, and said the attacks were using Rapid7's PoC [5]. That is not adaptation or reverse engineering. That is copy and run.

Microsoft's own description was already sufficient to justify emergency handling. The company characterised CVE-2026-55040 as a weak authentication issue allowing a security feature bypass over a network [3]. "Exploiting this vulnerability could allow an attacker to disclose files and modify data," Microsoft said, adding that "in a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection" [3]. Unauthenticated, network-reachable, read and write. The advisory still does not mention exploitation, though delays of several days between confirmed attacks and an updated Microsoft advisory are routine [6].

The chaining risk raises the ceiling. Rapid7 also reported CVE-2026-63520, a separate SharePoint flaw that can be combined with CVE-2026-55040 to achieve unauthenticated remote code execution on servers [7]. Microsoft addressed CVE-2026-63520 in its August Patch Tuesday updates, and there is no indication it is being exploited [8]. For unpatched estates, that means the August cycle is not a separate maintenance question from the July one: the two together move the outcome from file disclosure and data modification to code execution.

CISA had already flagged this. The agency recently urged organisations to ensure SharePoint instances were up to date and protected in light of a new wave of attacks, and warned at the time that CVE-2026-55040 could be exploited in the wild [9]. It has not yet added the flaw to the KEV catalogue, which already lists more than a dozen SharePoint bugs [10]. Federal remediation clocks therefore have not started, even though the exploitation is confirmed by a third party.

Context on volume: CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has surfaced this summer, following CVE-2026-50522, CVE-2026-58644, CVE-2026-56164 and CVE-2026-45659 [12]. There is no public information on who is behind any of that activity [13]. Also worth noting for capacity planning: August Patch Tuesday carried 421 CVEs including one exploited zero-day [14].

Watch for a KEV addition for CVE-2026-55040 and for Microsoft to revise the advisory's exploitation status [6][10]. Watch for the chained CVE-2026-63520 path to appear in honeypot data, which would be the shift from data theft to server compromise [7][8]. And watch how long the deferred July patch survives as a deferral once attribution to a named actor appears [13].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories