Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Adds Microsoft SharePoint Weak Authentication Vulnerability to KEV List

CISA added a critical Microsoft SharePoint authentication flaw to its KEV catalog after CVE-2026-55040 was confirmed in active exploitation , urging organizations to secure affected on-premises environments. CVE-2026-55040 is a weakness in Microsoft SharePoint’s authentication handling that can allow an unauthenticated attacker to bypass a security feature remotely. The issue is associated with CWE-1390, which covers weaknesses in authentication mechanisms. An attacker does not need legitimate SharePoint credentials to exploit the flaw, making internet-facing deployments a particularly high-risk target. Technical reporting indicates that the vulnerability affects the JSON Web Token validation path in SharePoint. Attackers may forge authentication tokens that SharePoint accepts as valid, allowing them to impersonate site users and potentially administrators.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-33824   (CVSS score: 9.8)  – Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • CVE-2026-55040   (CVSS score: 9.1) Microsoft SharePoint Weak Authentication Vulnerability • CVE-2026-59310   (CVSS score: 9.8)   Broadcom VMware vCenter Path Traversal Vulnerability • CVE-2026-65400  Apple macOS Improper Authentication Vulnerability CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability • CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability • CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability • CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-55040 - Microsoft SharePoint Weak Authentication Vulnerability

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates. “The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said. “Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the … More → The post Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers Actively Exploiting Microsoft SharePoint Vulnerability Following PoC Release

Threat actors have wasted no time weaponizing a newly disclosed Microsoft SharePoint authentication bypass, launching real-world attacks against internet-facing servers just hours after security firm Rapid7 published a technical breakdown and proof-of-concept exploit for the flaw. The vulnerability, tracked as CVE-2026-55040 and carrying a critical CVSS score of 9.1, allows a remote, unauthenticated attacker to forge a valid authentication token and impersonate any SharePoint user, including a site administrator, without ever needing a password or session cookie. Threat intelligence firm Defused confirmed the exploitation trend after observing suspicious activity hitting its SharePoint honeypots, warning that attackers were “now using the @rapid7 POC for CVE-2026-55040” against exposed systems.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9. 1), a critical SharePoint authentication bypass patched in July, within days of Rapid7 releasing a public proof-of-concept on August 12. The vulnerability allows an unauthenticated attacker impersonate any SharePoint user or administrator without valid credentials. Microsoft patched it in July’s Patch Tuesday, anyone who hasn’t applied that update is directly exposed. CVE-2026-55040 is a critical SharePoint authentication bypass. An unauthenticated attacker can exploit weaknesses in JWT validation to forge tokens and impersonate any SharePoint user, including administrators.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9. 1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Microsoft SharePoint RCE Flaw Chains Allow Unauthenticated Server Takeover

A newly disclosed Microsoft SharePoint Server vulnerability is raising urgent concerns for enterprise defenders after researchers demonstrated how it can be combined with an earlier flaw to enable unauthenticated remote code execution (RCE). Tracked as CVE-2026-63520, the issue was identified by Rapid7 Labs as part of a zero-day research initiative and has been coordinated with Microsoft. On its own, the vulnerability allows an unauthenticated remote attacker to execute code over the network under specific conditions. More significantly, researchers said it forms the second stage of an exploit chain with CVE-2026-55040, a SharePoint vulnerability disclosed in July 2026 .

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9. 1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to disclosure. ⠀ CVE-2026-63520 affects all supported versions of Microsoft SharePoint, and certain versions of Microsoft Project Server and Microsoft Office Web Apps Server. For the purpose of our research, we focused solely on SharePoint.

·Rapid7 Blog
Read →
Vulnerabilities & Patches
Emerging1 src

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script . Figure 1: The Rapid7 Labs PoC for CVE-2026-55040. ⠀ A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline. Analysis The following technical analysis is based upon SharePoint Server Subscription Edition version 16. 0. 19725. 20210 . A critical authentication bypass vulnerability exists in SharePoint Server Subscription Edition's JWT token validation pipeline.

·Rapid7 Blog
Read →

You've reached the end of current stories for this search.