Home / Aug 14, 2026 / Story
0
#3 The Hacker News general August 13, 2026 at 06:09 UTC

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

By [email protected] (The Hacker News)

AI Summary

Threat actors began actively exploiting CVE-2026-55040 (CVSS 9.1), a critical Microsoft SharePoint authentication bypass patched in the July 2026 Patch Tuesday, within days of Rapid7 publishing a public proof-of-concept. The flaw stems from weak authentication logic and enables unauthenticated attackers to bypass security controls on SharePoint servers. Organizations running unpatched SharePoint instances should treat this as urgent given the active exploitation confirmed in the wild.

Relevance score: 89.0/100

# More from August 14