Microsoft SharePoint Weak Authentication Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.1Security Advisory

TL;DR 📌

  • Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
  • Highest CVSS: 9.1 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Fixed in 16.0.19725.20434 — upgrade to this release or later.
  • CVEs: CVE-2026-55040.

What it is

CVE-2026-55040 is a weak authentication flaw in Microsoft Office SharePoint that allows an unauthorised attacker to bypass a security feature over a network. The CVSS vector confirms no privileges and no user interaction are required (PR:N, UI:N), and the attack vector is network-based (AV:N), meaning an attacker only needs network reach to the SharePoint service to attempt exploitation.

The impact is scored as confidentiality-high with no listed integrity or availability impact (C:H/I:N/A:N), so the practical outcome is unauthorised access to data or content that authentication controls should otherwise gate, rather than modification or disruption.

The advisory does not detail the specific endpoint or mechanism beyond describing it as a weak authentication issue bypassing a security feature. Organisations should consult Microsoft’s advisory for the precise component and request path involved.

This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-08-18, so it is known to be exploited.

What to do

  • Patch to fixed version 16.0.19725.20434 or later. Given CISA KEV listing, treat this as a priority patch rather than routine maintenance.
  • Confirm your SharePoint deployment’s exact build number against 16.0.19725.20434 — do not assume a recent update already covers this CVE.
  • Given the network-based, unauthenticated access path, review external exposure of SharePoint services and restrict access where internet-facing instances are not required.
  • Check logs for anomalous authentication or access patterns predating patching, given the confirmed exploitation status.
  • Track Microsoft’s advisory (linked via the CVE record) for any additional mitigation guidance or affected component detail not yet reflected here.

For leadership 🧭

Executive summary. A critical SharePoint flaw lets attackers reach protected content over the network without credentials, and it is already listed as exploited in the wild. Given active exploitation and the low bar for attack, this needs patching on an emergency basis, not the next routine cycle.

Why it matters:

  • The flaw sits in Microsoft Office SharePoint’s authentication layer, so any exposed instance can be reached and bypassed by an attacker with no credentials and no user interaction required.
  • The CVSS vector shows a high confidentiality impact with no integrity or availability loss, meaning the realistic outcome is unauthorised access to documents, sites or content stores rather than tampering or downtime.
  • This CVE is in CISA’s Known Exploited Vulnerabilities catalogue, added 18 August 2026, confirming it is being used in real attacks rather than remaining theoretical.
  • Internet-facing SharePoint deployments are the most immediate concern since the attack vector is network-based and needs no prior access to the environment.

Now / Next / Later:

  • Now: Identify every SharePoint instance in your estate and check its exact build number against the fixed version 16.0.19725.20434 — do not assume a recent patch cycle already covers it.
  • Next: During your next change window, patch all affected SharePoint servers to 16.0.19725.20434 or later, prioritising any instance reachable from the internet, and review logs for anomalous authentication or access activity predating the patch.
  • Later: Reassess which SharePoint services genuinely need to be internet-facing, tighten network exposure accordingly, and build faster build-number verification into routine patch tracking so future weak-authentication issues are caught before they reach KEV status.

Source