← nejvýznamnější zprávy · všechny zprávy

poslední zpráva · zachyceno

SPOJENO PŘES CVE KEV ✓ EPSS 0.18

Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)

CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-08-21.

Číst originál na CISA KEV →

3 zprávy z 3 zdrojů · první CZ · EN/orig

Microsoft US

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-55040 9.1 3.1 · microsoft KEV ✓ 0.18

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 3

  1. · zachyceno · CISA KEV US nadpis události

    Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)

    CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-08-21.

  2. · Rapid7 US

    Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

    OverviewOn July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script.Figure 1: The Rapid7 Labs PoC for CVE-2026-55040.⠀A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or…

  3. · Microsoft Security US

    CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability

    Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.