August 2026 was a brutal patch month. Microsoft’s Patch Tuesday fixed 421 CVEs including an exploited zero-day, and CISA added four critical bugs — all above CVSS 9.0 — to its Known Exploited Vulnerabilities catalog in a single week. The one moving fastest: CVE-2026-55040, a weak-authentication flaw in Microsoft SharePoint.
What CVE-2026-55040 does
The bug lets an unauthorized attacker bypass a security feature and reach SharePoint without valid credentials. The dangerous part is the timeline: within hours of the technical write-up going public, security teams were watching active exploitation against unpatched on-premises servers. Internet-facing SharePoint is a goldmine — it holds documents, drives internal collaboration, and often bridges into the wider network.
It wasn’t alone
- VMware vCenter (CVE-2026-59310) — a suspected APT was exploiting it in the wild by August 3; by August 7, responders tracked 361 compromised hosts across 47 countries, some used to deploy Babuk-derived ransomware.
- Windows IKEv2 (CVE-2026-33824) — a double-free in VPN key exchange, tied to a threat actor also running an AI-assisted autonomous hacking campaign.
- SAP Commerce Cloud (CVE-2026-58231) — exploited within 72 hours of disclosure.
The pattern: exploitation is now measured in hours
The window between a public advisory and mass exploitation has collapsed. “We patch on our monthly cycle” is no longer a strategy for internet-facing systems — for actively-exploited bugs it’s an open door. The two questions that matter: do you actually know your full internet-facing attack surface, and if an attacker lands on one host, how far can they move?
How we help
We validate the real perimeter with external network penetration testing, test lateral movement and blast radius with internal network penetration testing, and check SharePoint and other web apps the way an attacker does with web application penetration testing.
Know your exposure before the next advisory drops. Explore external network penetration testing — get a fixed-price quote.