Dispatch
Attackers began exploiting SharePoint CVE-2026-55040 on August 13, hours after a public proof-of-concept
Threat actors started actively exploiting CVE-2026-55040 (CVSS 9.1), a critical SharePoint authentication bypass, on August 13, 2026 after Rapid7 published proof-of-concept code. The flaw lets a remote unauthenticated attacker impersonate any user including an administrator, disclosing files and modifying data; Microsoft patched it in the July 2026 Patch Tuesday. It is the fifth SharePoint vulnerability under active exploitation, and reporting notes a significant portion of the discovery work was performed by an AI agent — a concrete data point on offensive-security automation shortening the patch-to-exploit window.
↳ Follow the thread