CVE-2026-55040
Actively exploited. CVE-2026-55040 is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild, and US federal agencies are required to remediate it under BOD 22-01. Treat patching as urgent.
Number: AL26-017 Date: July 15, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on July 14, 2026 Footnote 1 , the Cyber Centre issued AV26-698 Footnote 2 on July 14, 2026. Tracked as CVE-2026-55164 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function (CWE-306) Footnote 4 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to elevate privileges over a network. Tracked as CVE-2026-55040 Footnote 5 Footnote 6 , this vulnerability is a Weak Authentication (CWE-1390) Footnote 7 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to bypass a security feature over a network. Tracked as CVE-2026-58644 Footnote 8 , this vulnerability is a Deserialization of Untrusted Data (CWE-502) Footnote 9 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to execute code over a network. Microsoft is aware of exploitation of CVE-2026-56164 and other previously released SharePoint related vulnerabilities. CVE-2026-56164 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog Footnote 10 on July 14, 2026. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected prod
CSIRTS triage
- What
- There are critical vulnerabilities affecting Microsoft SharePoint Server that allow unauthorized access to critical functions.
- Who is affected
- Deployments of Microsoft SharePoint Server are affected by these vulnerabilities.
- Urgency
- Remediation is urgent due to active exploitation and the critical severity of the vulnerabilities.
- Action
- Apply the latest security updates provided by Microsoft.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-55040
Get an email if CVE-2026-55040 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Exploitation confirmedAlready exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 74% of all EPSS-scored CVEs.
Advisory coverage (7)
- unknownexploitedNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Officencsc-nl · 2026-07-21
- unknownexploitedNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Officencsc-nl · 2026-07-17
- criticalexploitedAL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and…cccs · 2026-07-15
- unknownexploitedNCSC-2026-0237 [1.00] [M/H] Vulnerabilities fixed in Microsoft Officencsc-nl · 2026-07-14
- criticalCVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a…nvd · 2026-07-14
- unknownexploitedCISA Urges SharePoint Hardening After New Exploitationscisa · 2026-07-14
- criticalCVE-2026-55040: Microsoft SharePoint Server Security Feature Bypass Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-55040)