SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

2026-08-13T14:51:36Zb57453f486a5688ac93a02b20347d2516103fc7d4a57d5fb75790af7597f530f
CVE-2026-50656CVE-2026-53413CVE-2026-55040AI-assisted attacksChina-linked threat actorDDoSLazarus GroupMicrosoft DefenderNorth KoreaSharePointStorm-1175WindowsZoomactive exploitationauthentication bypassbotnetcloud securitydata exfiltrationextortionpublic exploitransomwareremote code executionsupply chain disruptionzero-clickzero-day

What happened

The feed reports active exploitation of critical vulnerabilities, including SharePoint CVE-2026-55040 authentication bypass, a public exploit for the Microsoft Defender RoguePlanet patch bypass, and a Zoom zero-click remote-code-execution flaw. It also covers ransomware, North Korean and China-linked campaigns, autonomous AI-assisted intrusion activity, Android TV botnet evolution, supply-chain disruption, and data extortion operations. The most urgent item is the actively exploited unauthenticated SharePoint flaw with a reported CVSS score of 9.1.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b57453f486a5688ac93a02b20347d2516103fc7d4a57d5fb75790af7597f530f
Enrichment time
2026-08-13T14:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit · Baitaphish