SharePoint CVE-2026-55040: half the chain is still open
Microsoft split one SharePoint exploit chain across two Patch Tuesdays. You patched the auth bypass in July; the RCE half lands August 11. Plan the window now.
If you run on-premises SharePoint Server and patched in July, you closed half a bug. CVE-2026-55040 was one link in a two-link chain that Rapid7 built to unauthenticated remote code execution — and Microsoft is shipping the fixes across two separate Patch Tuesdays. The second half is scheduled for August 11. Your July patch report says "done." The chain says otherwise.
What actually happened
Rapid7 Labs ran a zero-day research project against Microsoft SharePoint and found two vulnerabilities that chain into unauthenticated RCE against a vulnerable on-premises server. Senior Principal Security Researcher Stephen Fewer disclosed them to Microsoft on May 18, 2026.
The first link, CVE-2026-55040, is a CVSS 9.1 authentication bypass caused by several issues in SharePoint's JWT token validation pipeline. A remote unauthenticated attacker who knows a target's Active Directory Security ID or User Principal Name can forge a token the server accepts, then operate as that user — including a site administrator. Those identifiers are not secrets; they're derivable from an email address in plenty of environments. It was patched and publicly disclosed on July 14, 2026.
The second link is the RCE. Per Rapid7, Microsoft confirmed remediation would be split across two scheduled update cycles: the authentication bypass in July, the RCE component in August. August's Patch Tuesday is the 11th.
Why split patching matters for your business
Most patch processes are built around a monthly checkbox: bulletin drops, updates apply, ticket closes. That process has no state for "this fix is one of two." A vulnerability that spans cycles slips straight through it, because every artifact your process produces in July looks complete.
The exposure here is real but bounded, and worth stating plainly rather than dramatizing. With the July patch applied, the published bypass is closed — an attacker can't currently walk the front of the chain. The risk is the shape of the thing: a known-vulnerable RCE sitting in a product with a documented history of being chained, in the specific window before its fix ships. That is not a fire drill. It is a reason to have the August window already scheduled instead of discovering it on the 12th.
So: confirm July actually deployed everywhere, including the SharePoint box nobody logs into that still serves an old intranet. Book the maintenance window for August 11 now, before it competes with whatever else lands that week. And if that server is reachable from the internet without needing to be, this is the month to put it behind the VPN — the cheapest mitigation for an unpatched RCE is not being able to reach it. We've made the same argument about machine-key rotation on SharePoint: the patch is the start of the work, not the end of it.
Key takeaways
- CVE-2026-55040 (CVSS 9.1) is a JWT auth bypass in on-premises SharePoint Server, patched July 14
- It is one half of a Rapid7 chain to unauthenticated RCE; the RCE fix ships in the August cycle
- August Patch Tuesday is the 11th — schedule the window before the week fills up
- Impersonation only needs a target's AD Security ID or UPN, not a password
- Verify the July update actually landed on every SharePoint host, including forgotten intranet servers
Not sure which servers are still exposed? We map what your business actually runs, what's reachable from outside, and what breaks if it goes down — then we fix the parts that shouldn't be internet-facing. Book an exposure review or see how we work.
Sources: Rapid7 — CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass.
- #cve-2026-55040
- #sharepoint
- #patch-management
- #patch-tuesday
- #on-premises
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Palantir's 149% US commercial quarter: the stack is the product
Palantir Q2 2026 revenue grew 93% to $1.9B with US commercial up 149%. What buying the whole stack instead of renting a model means for smaller operators.
Read itTruth API: platform data now has a latency tier
Trump Media's Truth API went live August 1, pitched to trading firms at up to $100k/month for millisecond delivery. Public data is being unbundled by speed.
Read it