Security Advisory: Actively Exploited SharePoint Vulnerability
Microsoft SharePoint Server 2016, 2019, and the SharePoint Server Subscription Edition are affected by a critical authentication bypass vulnerability tracked as CVE-2026-55040. Discovered in July 2026, this flaw allows unauthenticated attackers to bypass security features over the network. The vulnerability received a CVSS 3.1 score of 9.1 (CRITICAL) and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026, with a remediation due date of August 21, 2026. Active exploitation has been confirmed in the wild, making this one of the most pressing SharePoint security issues of the year.
Attack Overview
The vulnerability stems from improper handling of authentication tokens in Microsoft Office SharePoint. An attacker can exploit this weakness without valid credentials, gaining the ability to bypass security controls and execute operations with elevated privileges. The attack vector is network-based, requires low attack complexity, and needs no privileges or user interaction.
Affected Products and Versions
- Microsoft SharePoint Server 2016: versions up to (excluding) 16.0.5561.1001
- Microsoft SharePoint Server 2019: versions up to (excluding) 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition: versions up to (excluding) 16.0.19725.20434
Organizations using internet-facing SharePoint deployments should prioritize assessment of their exposure to this vulnerability.
CISA KEV Catalog Impact
CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on August 18, 2026. The entry includes:
- Date Added: 2026-08-18
- Due Date: 2026-08-21 (per CISA BOD 26-04)
- Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk
Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to patching guidelines. The SSVC framework categorizes this vulnerability with active exploitation, automatable technical impact, and total business impact.
Detection Guidance
Detecting exploitation requires monitoring for unauthenticated access attempts to SharePoint endpoints. Key indicators include:
- Unexplained authentication events in SharePoint logs
- Access from unexpected source IPs or geographies
- Unusual API call patterns to SharePoint endpoints
Sigma and YARA rules have been published by the security community for detection, focusing on authentication bypass patterns and unusual SharePoint service account activity.
Mitigation and Patching
Immediate Priority: Apply the Microsoft security update immediately. The CISA KEV entry mandates action by August 21, 2026.
Microsoft Update Paths:
- SharePoint Server 2016: Update to version 16.0.5561.1001 or later
- SharePoint Server 2019: Update to version 16.0.10417.20175 or later
- SharePoint Server Subscription Edition: Update to version 16.0.19725.20434 or later
Temporary Mitigations (if immediate patching is not possible):
- Restrict network access to SharePoint servers via firewall rules
- Implement additional authentication layers (VPN, Azure AD Conditional Access)
- Monitor SharePoint authentication logs for anomalous activity
- Disable unnecessary SharePoint services or endpoints exposed to the internet
CISA Guidance: Per BOD 26-04, organizations must prioritize security updates based on risk. For KEV entries, the required action is to apply mitigations per vendor instructions. Stakeholders should evaluate internet exposure and follow applicable patching guidelines.
Comparison with Previous SharePoint Vulnerabilities
CVE-2026-55040 is distinct from previous SharePoint authentication vulnerabilities such as CVE-2023-24935 and CVE-2022-26366. While earlier flaws also involved authentication bypass, CVE-2026-55040 is notable for:
- CVSS 9.1 severity (higher than many prior SharePoint CVEs)
- Active exploitation in the wild within days of disclosure
- CISA KEV catalog inclusion with short remediation window
- Broad affected version range across SharePoint 2016, 2019, and Subscription Edition
The JWT token authentication bypass pattern represents an evolution in SharePoint attack techniques, requiring updated detection and mitigation strategies.
Frequently Asked Questions
Q: Is my SharePoint deployment affected? A: Check your SharePoint version against the affected version ranges listed above. If you're running a version prior to the minimum listed, your deployment is affected. Consult with your SharePoint administrator if uncertain.
Q: Has this vulnerability been exploited in the wild? A: Yes. CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog on August 18, 2026, with evidence of active exploitation. The due date for mandated remediation was August 21, 2026.
Q: Do I need to disconnect SharePoint if I can't patch immediately? A: Not necessarily. CISA guidance focuses on applying mitigations per vendor instructions. If mitigations are unavailable and the system is internet-exposed, discontinuing use may be recommended. Evaluate your specific risk profile.
Q: Will the patch break customizations or extensions? A: As with any security update, there is a risk of compatibility issues with custom SharePoint extensions, solutions, or configurations. Test the update in a non-production environment first. Roll back is possible if issues arise.
Q: Does this affect SharePoint Online (Microsoft 365)? A: The specific CVE-2026-55040 affects on-premises SharePoint Server 2016, 2019, and Subscription Edition versions. SharePoint Online/Microsoft 365 may have different update timelines. Check the Microsoft 365 Roadmap for SharePoint update announcements.
Q: How does this relate to other CISA KEV entries? A: CVE-2026-55040 is the 18th SharePoint-related vulnerability added to the CISA KEV catalog in 2026, joining other actively exploited Microsoft vulnerabilities. The common theme is authentication/authorization flaws in Microsoft server products.
Sources
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-55040
- Microsoft MSRC Advisory: CVE-2026-55040
- NVD: CVE-2026-55040 Detail
- Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass CVE-2026-55040
- GitHub PoC Repository: sfewer-r7/CVE-2026-55040
- CISA Binding Operational Directive 26-04
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.