Act
active
CVE-2026-55040: Unauthenticated RCE in SharePoint Server, PoC Public
- Engineer — Act: Public PoC on GitHub for a CVSS 9.1 unauthenticated RCE across SharePoint Server Subscription Edition, 2019, and 2016 means exploitation risk is immediate even without KEV listing; apply Microsoft’s patch for CVE-2026-55040 across all affected on-prem SharePoint instances this week.
- SOC/IR — Plan: No confirmed in-the-wild exploitation yet (EPSS 0.02, no KEV), but a public PoC for unauthenticated RCE warrants building SharePoint-specific detections now — hunt for anomalous unauthenticated requests to SharePoint REST/SOAP endpoints and tune alerts on privilege escalation patterns in SharePoint audit logs before active campaigns emerge.
- Leader — Plan: A CVSS 9.1 unauthenticated RCE with public PoC against widely deployed SharePoint Server warrants confirming on-prem SharePoint scope with your team and ensuring patch prioritization this sprint — escalate to Act if exploitation is observed in the wild.
- Signals: CVE-2026-55040 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.