CVE-2026-55040 · Critical · CISA KEV

Microsoft SharePoint Weak Auth Bypass: Critical Risk, In-the-Wild Exploitation

Threat Engine Auto-Feed · data current as of 2026-08-19

A weak authentication vulnerability in Microsoft SharePoint allows unauthorized attackers to bypass security features over a network. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has a high EPSS percentile indicating significant exploitation probability.

  • CVSS:
  • EPSS percentile: 0.89591
  • Exploitation pressure: 79/100 (Critical)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 90th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability stems from a flaw in how SharePoint verifies user identities, allowing an attacker to circumvent authentication mechanisms. This means that even without valid credentials, an attacker can bypass security checks designed to protect the system.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations heavily reliant on Microsoft SharePoint for internal collaboration and document management
  • Financial services organizations targeted by financially motivated groups like FIN7, LockBit affiliates, and APT38
  • Technology sector organizations targeted by espionage groups like APT29 and Scattered Spider

Misconfigurations that escalate it

  • SharePoint instances with default or weak authentication configurations
  • Lack of multi-factor authentication (MFA) enforcement for SharePoint access
  • Insufficient network segmentation isolating SharePoint servers from untrusted networks

High-impact scenarios

  • Unauthorized access to sensitive documents and data stored in SharePoint
  • Potential for data exfiltration and intellectual property theft
  • Lateral movement within the network after initial SharePoint compromise
  • Disruption of business operations reliant on SharePoint services

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor SharePoint access logs for unusual login patterns or unauthorized access attempts
  • Implement robust logging and alerting for authentication bypass attempts
  • Regularly review SharePoint security configurations and user permissions

Contain

  • Isolate affected SharePoint servers from the network if compromise is suspected
  • Force password resets for all SharePoint users if a breach is confirmed
  • Block suspicious IP addresses attempting to access SharePoint

Patch

  • Apply all available security updates and patches from Microsoft for SharePoint immediately

Frontier verdict — Critical

Critical priority due to active exploitation in the wild (CISA KEV) and high EPSS, impacting core collaboration platforms.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.