Threat intel / CVE tracker
CVE-2026-55040
Critical KEV · actively exploited PoC availableCVSS base score
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NWeak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Vendor
microsoft
Product
sharepoint server
Affected
microsoft sharepoint server
Weakness
CWE-1390 · Vulnerability
Published
Jul 14, 2026
Last modified
Aug 19, 2026
CVSS version
v3.1
Views
3
// References & exploits
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040PatchVendor Advisoryhttps://github.com/sfewer-r7/CVE-2026-55040PoChttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040PoCThird Party Advisoryhttps://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/US Government Resource