Critical SharePoint Authentication Bypass Enables Unauthenticated Remote Code Execution via Network Exploitation
A critical authentication bypass in Microsoft SharePoint allows attackers to circumvent security features over a network. This flaw is the first half of a two-step exploit chain designed to achieve unauthenticated remote code execution. Patch your SharePoint environments immediately to mitigate this risk.
Summary
Microsoft has released a patch for CVE-2026-55040, a critical vulnerability in Microsoft SharePoint that enables an unauthorized attacker to bypass security features via a network connection. The flaw was discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer and was published in coordination with Microsoft.
While the current patch addresses the authentication bypass, it is only one part of a larger threat profile. When paired with a second vulnerability, this flaw can be used to execute code remotely on a vulnerable SharePoint server without requiring any prior authentication or credentials.
Technical details
The vulnerability, tracked as CVE-2026-55040, carries a CVSS score of 9.1. It functions by allowing an attacker to bypass specific security controls within the SharePoint environment.
The full impact of this flaw is realized through an exploit chain. The first step involves using CVE-2026-55040 to bypass authentication; however, the second vulnerability required to complete the remote code execution (RCE) chain remains under embargo. Microsoft is expected to release the patch for that second component during the August 2026 Patch Tuesday cycle.
Affected products and fixed versions
Patches are currently available for several versions of SharePoint. Because certain older versions reach their extended end date on July 14, 2026, administrators should prioritize upgrading to supported editions where possible.
| Product | Status |
|---|---|
| Microsoft SharePoint Server 2016 | Patch Available |
| Microsoft SharePoint Server 2019 | Patch Available |
| Microsoft SharePoint Server Subscription Edition | Patch Available |
Why this matters for defenders
The risk associated with CVE-2026-55040 is heightened by the fact that it acts as a gateway for full system compromise. Even though the second half of the RCE chain is not yet public, the existence of the first vulnerability provides the necessary foothold for an attacker to move toward code execution.
Furthermore, Microsoft's product lifecycle changes create urgency for many organizations. SharePoint Server 2016 and 2019 reach their extended end dates on July 14, 2026. For those running these versions, there is no Extended Security Update (ESU) available, meaning the current patches are critical before support ends entirely.
Defender guidance
Apply the security updates provided in the July 2026 Patch Tuesday cycle to all instances of SharePoint Server 2016, 2019, and Subscription Edition.
Because the second half of the RCE chain will not be patched until August 2026, defenders should treat any successful authentication bypass as a high-priority incident. Monitor network traffic for unusual patterns targeting SharePoint services that could indicate an attempt to exploit this specific weakness.
Sources
- https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-58617
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-58595
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-48561
