A researcher published proof-of-concept code for a Microsoft SharePoint flaw on 11 August, and attackers were exploiting it within hours. On 18 August, the US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability, tracked as CVE-2026-55040, to its Known Exploited Vulnerabilities catalogue after confirming real-world attacks. That’s a different, newer flaw to the SharePoint issue we covered back in July — this one is more severe, because it needs no credentials at all.
The bug is a JSON Web Token authentication bypass. In plain terms, it lets a remote attacker forge a valid login token and impersonate any user on a vulnerable SharePoint site, including an administrator, without a password, a phishing email, or any interaction from a real person. Chained with a second flaw, CVE-2026-63520, it becomes fully unauthenticated remote code execution: complete takeover of the server. Microsoft patched both in its August updates, but researchers estimate over 8,500 on-premise SharePoint servers are still sitting exposed on the open internet.
Who this actually affects
If your business runs SharePoint Online as part of Microsoft 365, you can relax — Microsoft operates and patches that infrastructure directly, and there’s nothing for you to do. This flaw only bites on-premise SharePoint deployments: SharePoint Server Subscription Edition, SharePoint Server 2019, and older on-site installations. That’s the setup you’re more likely to have if your IT estate grew organically over the years, came with an acquisition, or was built around a compliance requirement that pushed you away from the cloud.
The honest first step, as with most of these stories, is knowing what you’re running. A surprising number of SMEs inherited an on-premise server from a previous IT provider and haven’t checked its patch status in months. If nobody in your business can say with confidence “we’re on SharePoint Online” or “we’re on-premise and patched,” that’s this week’s question to answer.
Why the speed here matters
What makes this one worth an actual response, rather than a mental note, is the timeline. Proof-of-concept code went public on 11 August; honeypots were recording exploitation attempts within a day; CISA confirmed active attacks and added it to its exploited-vulnerabilities list a week later. That compression — from public disclosure to real attacks to confirmed exploitation — is much faster than the weeks or months businesses often assume they have to patch something. Rapid7, the firm that disclosed the flaws, has confirmed that patching CVE-2026-55040 alone is enough to break the attack chain, since it’s the first link both vulnerabilities depend on. You don’t need to solve both at once — you need to close the door the attacker is actually using.
If you’re not confident your on-premise systems are being tracked and patched on this kind of timescale, that’s a gap worth closing properly rather than papering over after the next scare. CoolCoding can audit exactly what you’re running, where it’s exposed, and whether your patch management actually keeps pace with disclosures like this one — rather than finding out from a client or an insurer after the fact.
Building a patching habit, not just a one-off fix
Applying this month’s update solves this month’s problem. The harder, more useful question is whether your business has any routine at all for tracking what’s still outstanding across the systems you run — and whether “we’ll get to it” is really a plan or just a hope that nothing bad happens in the meantime. A short monthly check-in with whoever manages your IT, specifically asking what’s unpatched and why, costs almost nothing and closes exactly the kind of gap this vulnerability exploited. Most businesses that get caught out by a flaw like this one weren’t unaware a patch existed — they just didn’t have a clear owner making sure it actually got applied.
The takeaway
Confirm whether your business runs SharePoint Online or an on-premise server today, not next week. If it’s on-premise, apply August’s Microsoft update — particularly the fix for CVE-2026-55040 — and don’t assume “we’ll get to it” is fast enough this time. When a flaw goes from public proof-of-concept to active exploitation in under 24 hours, the gap between “patch available” and “patch applied” is exactly where you don’t want your business sitting.