Attackers have started exploiting a critical SharePoint flaw now that working attack code is public. The bug, tracked as CVE-2026-55040, is an authentication bypass: it lets an attacker get in without a valid login. Microsoft already patched it back in July. If you run SharePoint and haven’t applied that update, you’re exposed right now, not in theory.
Here’s the plain-language version of what’s happening.
What the flaw actually does
SharePoint is where a lot of businesses keep their documents. Contracts, client files, HR records, internal wikis. If you use Microsoft 365, you’re touching SharePoint whether you think about it or not, because it’s the engine behind file storage in Teams and OneDrive for Business. Plenty of firms also run SharePoint Server on their own hardware, which is the version most at risk here.
The flaw is what security people call a “security feature bypass that stems from weak authentication,” per The Hacker News. Strip out the jargon and it means this: the door that’s supposed to check who you are can be tricked into opening for someone who never proved they belong. It carries a severity score of 9.1 out of 10, which is about as bad as these get.
The dangerous part is the timing. Microsoft shipped the fix in July. Then researchers published a proof-of-concept, which is sample code that demonstrates how to exploit the hole. Once that goes public, the window between “interesting research” and “criminals mass-scanning the internet for unpatched servers” is measured in days. That window has closed. Attacks are live now.
Why this hits small businesses harder
Big companies have a patch team. Someone whose actual job is to test and roll out updates the week they drop. Most small firms don’t. The SharePoint server got set up years ago by someone who’s since moved on, it’s been running fine, and nobody’s logged into the admin console in months. That “it just works” server is exactly what gets caught.
An authentication bypass is especially nasty because it skips the step attackers usually have to fight through. They don’t need your password. They don’t need to phish an employee. They don’t need MFA codes. They walk past the login screen entirely. From there, depending on your setup, they can read files, plant malware, or use that foothold to move deeper into your network. This is often step one in a ransomware attack: get in somewhere quiet, look around, then hit everything at once.
That same Patch Tuesday from Microsoft covered nearly 400 flaws total, including a Windows bug already being exploited in the wild, as Krebs on Security reported. Microsoft says the flood is partly because AI is now very good at finding these holes. The volume isn’t slowing down. The lesson isn’t “panic about one bug,” it’s that patching has quietly become a monthly job you can’t skip.
What to do this week
If you run SharePoint Server on your own equipment, this is the urgent one. Apply the July 2026 security update for SharePoint if you haven’t. It closes CVE-2026-55040. If you’re not sure whether it’s installed, that uncertainty is your answer: check today.
A few specifics to hand to whoever runs your IT:
- Confirm the July SharePoint patch is applied on every SharePoint server you own. There is no reason to wait on this one.
- If your SharePoint server is reachable from the open internet and doesn’t need to be, put it behind a VPN or restrict access by IP. Fewer front doors, fewer problems.
- Apply the rest of August’s Windows updates while you’re in there, especially on any machine an attacker could reach. One of them is already being exploited.
- Check your logs for odd SharePoint access, especially requests that succeeded without a normal login. If you don’t have logging turned on, turn it on.
If you’re a cloud-only Microsoft 365 shop with no server of your own, Microsoft patches the hosted side for you, so this specific flaw is less of a fire drill. But it’s a good moment to confirm nobody stood up a self-hosted SharePoint box years ago that everyone forgot about. Those forgotten servers are where breaches live.
Staying current on patches across Windows, Microsoft 365, and the servers underneath them is exactly the kind of thing that quietly falls through the cracks at a busy small business. It’s a big part of what we handle for clients, both on the Microsoft 365 side and with ongoing managed IT and patching, so a flaw like this gets closed before anyone’s writing a headline about it.
If you’re not sure whether your SharePoint or your patching is current, don’t guess. Book a free 15-minute consult and we’ll tell you where you stand.