M365 Change Tracker

← All changes · security · CVE-2026-55040

CVE-2026-55040CriticalImmediate

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Severity Critical  ·  Urgency Immediate  ·  Exploited in the wild

Why it matters: Exploited in the wild — CISA fix-by 2026-08-21

Remediate by Aug 21, 2026 · passed 3d ago

Security Feature Bypass · Critical · CVSS 9.1 · Exploited in the wild. Affects: SharePoint Server.

CVSS 9.1EPSS 5.5%Exploited in the wildCISA remediation due 2026-08-21 (passed 3d ago)Security update published 2026-08-21Applies to On-premisesKB5002891NVDCISA KEV

Affected: SharePoint Server

Related changes

View at Microsoft →