SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
2026-08-13T08:51:39Z•018eb960d0d9ff782271db90614fc139094cb1e4406346d1f762f008df645ba9
CVE-2026-50656CVE-2026-53413CVE-2026-55040AI-assisted attacksAndroid TVChina-linked threat actorsDDoS botnetLazarusMicrosoft Patch TuesdayNorth KoreaSharePointStorm-1175Zoomactive exploitationauthentication bypassdata exfiltrationextortionpublic PoCransomwareremote code executionzero-day
What happened
Security Affairs reports active exploitation of a critical SharePoint authentication-bypass vulnerability following release of a public proof of concept, alongside ransomware, zero-day, supply-chain, botnet, autonomous intrusion, and data-extortion activity. The most urgent issue is CVE-2026-55040, reportedly enabling unauthenticated administrator impersonation with a CVSS score of 9.1. Other notable developments include StormEncryptor ransomware, Lazarus exploitation of a Windows zero-day, a Microsoft Defender patch bypass, a wormable DNS RCE, and a critical Zoom zero-click RCE.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 018eb960d0d9ff782271db90614fc139094cb1e4406346d1f762f008df645ba9
- Enrichment time
- 2026-08-13T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.