CISA added a critical Microsoft SharePoint authentication flaw to its KEV catalog after CVE-2026-55040 was confirmed in active exploitation, urging organizations to secure affected on-premises environments.
CVE-2026-55040 is a weakness in Microsoft SharePoint’s authentication handling that can allow an unauthenticated attacker to bypass a security feature remotely.
The issue is associated with CWE-1390, which covers weaknesses in authentication mechanisms. An attacker does not need legitimate SharePoint credentials to exploit the flaw, making internet-facing deployments a particularly high-risk target.
Technical reporting indicates that the vulnerability affects the JSON Web Token validation path in SharePoint. Attackers may forge authentication tokens that SharePoint accepts as valid, allowing them to impersonate site users and potentially administrators.
This can give an intruder access to sensitive documents, collaboration sites, configuration data, and administrative functions without stealing a password or session cookie.
The vulnerability is reported to affect on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
SharePoint Online is not affected by this specific issue. Microsoft reportedly released fixes during its July 2026 security updates. However, organizations that delayed patching may now face exploitation attempts following the public availability of proof-of-concept code.
CISA added the vulnerability to the KEV catalog on August 18, 2026, and set a remediation due date of August 21, 2026. While CISA’s entry does not identify ransomware use.
The agency’s KEV inclusion is a strong signal that defenders should treat the vulnerability as an urgent incident-response and patch-management priority
Organizations should apply Microsoft’s available mitigations and security updates immediately, with priority given to externally accessible SharePoint servers.
Administrators should also verify that updates are fully deployed across every server in a SharePoint farm and complete any required post-installation configuration steps. A partially patched farm may leave the environment exposed.
Security teams should review SharePoint and identity logs for suspicious activity that could indicate attempted token forgery or unauthorized administrative access.
Useful indicators include unexpected service-to-service authentication events, unusual administrator logins, unknown account changes, abnormal access to sensitive sites, and network traffic from untrusted sources targeting SharePoint endpoints.
For example, an attacker who submits a forged token may appear in logs as a trusted SharePoint user rather than as an anonymous external visitor. That makes log review and forensic triage as important as applying the patch.
CISA advised stakeholders to follow vendor instructions, comply with Binding Operational Directive 26-04 risk-based patching guidance, assess each asset’s internet exposure, and follow applicable forensic-triage requirements. If effective mitigations are unavailable, organizations should consider removing the vulnerable product from service.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…