Close Menu
NCIJ Network NCIJ Network
    What's Hot

    California Officials Scrambled as Spring Wildfire Neared Former Nuclear Reactor Site, Emails Show

    August 12, 2026

    Nigeria’s new tax breaks put $50 billion deepwater oil & gas projects back in play

    August 12, 2026

    Posts claim Rosa Parks’ husband owned a car during bus boycotts. Here are the facts

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • California Officials Scrambled as Spring Wildfire Neared Former Nuclear Reactor Site, Emails Show
    • Nigeria’s new tax breaks put $50 billion deepwater oil & gas projects back in play
    • Posts claim Rosa Parks’ husband owned a car during bus boycotts. Here are the facts
    • US consumer inflation slows in July as energy prices briefly retreat | Inflation News
    • Trump denies orchestrating plane switch: ‘It’s only up to Secret Service’
    • Burnham to consider ban on disposable barbecues as wildfires rage in UK | Environment
    • Takeaways From the Wisconsin, Minnesota and South Carolina Primaries
    • Investor Nelson Peltz prepares bid for US burger chain Wendy’s
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SharePoint Vulnerability Exploited Shortly After PoC Release

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A SharePoint vulnerability patched last month is now being exploited in the wild, with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit.

    The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates.

    Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network.

    “Exploiting this vulnerability could allow an attacker to disclose files and modify data,” Microsoft said, adding, “In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection.”

    Rapid7 disclosed the technical details of CVE-2026-55040 on August 11, showing how a remote, unauthenticated attacker could exploit it to bypass authentication and perform operations as a SharePoint site user or administrator. The security firm also made a PoC script available.

    Threat intelligence firm Defused reported on August 12 that its honeypots have recorded exploitation attempts targeting CVE-2026-55040 and the attacks are leveraging the PoC released by Rapid7.

    Advertisement. Scroll to continue reading.

    Microsoft’s advisory still does not mention exploitation, but it’s not uncommon for the tech giant to only update its advisories days after attacks have been confirmed.

    Separately, Rapid7 on Tuesday reported discovering CVE-2026-63520, a SharePoint flaw that could be chained with CVE-2026-55040 to achieve unauthenticated remote code execution on servers.

    CVE-2026-63520 was addressed by Microsoft with its August Patch Tuesday updates, and there is no indication that it too is being exploited in attacks. 

    Surge in SharePoint vulnerability exploitation

    CISA recently urged organizations to ensure that their SharePoint instances are up to date and protected in light of a new wave of attacks.

    At the time, CISA warned that CVE-2026-55040 could also be exploited in the wild. The agency has yet to add the vulnerability to its KEV catalog, which currently includes over a dozen SharePoint flaws. 

    CVE-2026-55040 is the fifth SharePoint vulnerability whose exploitation has come to light this summer, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.  

    However, there does not appear to be any public information on who is behind the exploitation of these weaknesses.

    Related: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    Related: Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

    Related: Zoom Patches Zero-Click Code Execution Vulnerability

    Exploited PoC release SharePoint shortly Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    17 old software bugs that took way too long to squash

    The AI harness is the new attack surface

    Signal adds new security feature to thwart man-in-the-middle attacks

    New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

    Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    Early release scheme risks more serious crimes, probation chief warns

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    California Officials Scrambled as Spring Wildfire Neared Former Nuclear Reactor Site, Emails Show

    August 12, 2026

    Nigeria’s new tax breaks put $50 billion deepwater oil & gas projects back in play

    August 12, 2026

    Posts claim Rosa Parks’ husband owned a car during bus boycotts. Here are the facts

    August 12, 2026

    US consumer inflation slows in July as energy prices briefly retreat | Inflation News

    August 12, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    California Officials Scrambled as Spring Wildfire Neared Former Nuclear Reactor Site, Emails Show

    August 12, 2026

    Nigeria’s new tax breaks put $50 billion deepwater oil & gas projects back in play

    August 12, 2026

    Posts claim Rosa Parks’ husband owned a car during bus boycotts. Here are the facts

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.