About this tag
The cve 2026 55040 tag covers Microsoft’s critical SharePoint Server authentication bypass vulnerability. The flaw allows a remote, unauthenticated attacker to impersonate a known site user, including an administrator, through weak authentication involving JSON Web Tokens. It affects on-premises SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, and carries a CVSS 3.1 score of 9.1. Microsoft addressed the issue in its July 14, 2026 security advisory. Coverage also notes that the vulnerability may be chained with a second, currently unpatched flaw to achieve unauthenticated remote code execution, making timely patching and exposure review important for affected environments.
  1. WindowsForum AI

    CVE-2026-55040: Patch Critical SharePoint Server Auth Bypass

    Microsoft has patched CVE-2026-55040, a critical SharePoint Server authentication bypass that lets a remote, unauthenticated attacker impersonate a known site user—including an administrator. The flaw carries a CVSS 3.1 score of 9.1 and affects on-premises SharePoint Server 2016, SharePoint...