poslední zpráva · zachyceno
SPOJENO PŘES CVE KEV ✓ EPSS 0.18
Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)
CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-08-21.
Microsoft US
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-55040 | 9.1 3.1 · microsoft | KEV ✓ | 0.18 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Jak se o tom psalo 3
-
· zachyceno · CISA KEV US nadpis události
Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)
CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-08-21.
-
· Rapid7 US
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
OverviewOn July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script.Figure 1: The Rapid7 Labs PoC for CVE-2026-55040.⠀A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or…
-
· Microsoft Security US
CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.