• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-55040: pre-auth authentication bypass in Microsoft SharePoint

An unauthenticated attacker can bypass a security feature in Microsoft SharePoint to affect on-premises SharePoint Server installations; this is tracked as CVE-2026-55040. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the specified 16.x ranges listed by the vendor. An attacker only needs network access to reach the server — no valid account or user interaction is required — to exploit the weakness.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.1CRITICAL
EPSS
0.17535
CWE
CWE-1390
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA placed this vulnerability on the Known Exploited Vulnerabilities catalog with an August 21, 2026 remediation requirement, so prioritize applying vendor fixes or mitigations immediately.

What is CVE-2026-55040?

An unauthenticated attacker can bypass a security feature in Microsoft SharePoint to affect on-premises SharePoint Server installations; this is tracked as CVE-2026-55040. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the specified 16.x ranges listed by the vendor. An attacker only needs network access to reach the server — no valid account or user interaction is required — to exploit the weakness.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Microsoft SharePoint are affected?

BRANCHAFFECTEDFIXED
Microsoft SharePoint Enterprise Server 2016 16.x16.0.0 – before 16.0.5561.100116.0.5561.1001
Microsoft SharePoint Server 2019 16.x16.0.0 – before 16.0.10417.2017516.0.10417.20175
Microsoft SharePoint Server Subscription Edition 16.x16.0.0 – before 16.0.19725.2043416.0.19725.20434

Is CVE-2026-55040 being exploited?

CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog on 2026-08-18, and US federal agencies were required to remediate by 2026-08-21. Public exploit code is available.

How to fix CVE-2026-55040

  1. Apply the vendor updates to the fixed builds: 16.0.5561.1001 for Enterprise Server 2016, 16.0.10417.20175 for Server 2019, and 16.0.19725.20434 for Subscription Edition.
  2. If you cannot patch immediately, restrict network exposure of SharePoint servers (block internet access, limit access via firewall/VPN).
  3. Follow Microsoft guidance and monitor SharePoint logs and network traffic for anomalous activity against affected systems.

Frequently asked questions

Is CVE-2026-55040 being actively exploited?

CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog on 2026-08-18 and required remediation by 2026-08-21; public exploit code is also available.

Which SharePoint versions are affected by CVE-2026-55040?

Affected products are Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the 16.x ranges noted by the vendor (see affected builds).

Is there a patch for CVE-2026-55040?

Yes. Microsoft published fixed builds: 16.0.5561.1001 for Enterprise Server 2016, 16.0.10417.20175 for Server 2019, and 16.0.19725.20434 for Subscription Edition.

Does CVE-2026-55040 require authentication?

No. The vulnerability can be exploited over the network without valid credentials or user interaction against vulnerable SharePoint servers.

References