SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

2026-08-13T08:51:39Z018eb960d0d9ff782271db90614fc139094cb1e4406346d1f762f008df645ba9
CVE-2026-50656CVE-2026-53413CVE-2026-55040AI-assisted attacksAndroid TVChina-linked threat actorsDDoS botnetLazarusMicrosoft Patch TuesdayNorth KoreaSharePointStorm-1175Zoomactive exploitationauthentication bypassdata exfiltrationextortionpublic PoCransomwareremote code executionzero-day

What happened

Security Affairs reports active exploitation of a critical SharePoint authentication-bypass vulnerability following release of a public proof of concept, alongside ransomware, zero-day, supply-chain, botnet, autonomous intrusion, and data-extortion activity. The most urgent issue is CVE-2026-55040, reportedly enabling unauthenticated administrator impersonation with a CVSS score of 9.1. Other notable developments include StormEncryptor ransomware, Lazarus exploitation of a Windows zero-day, a Microsoft Defender patch bypass, a wormable DNS RCE, and a critical Zoom zero-click RCE.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
018eb960d0d9ff782271db90614fc139094cb1e4406346d1f762f008df645ba9
Enrichment time
2026-08-13T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit · Baitaphish