Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials. Microsoft shipped the July fix in three server updates:Subscription Edition KB5002882, build 16.0.19725.20434SharePoint Server 2019 KB5002883, build 16.0.10417.20175SharePoint Server 2016 KB5002891, build 16.0.5561.1001July 14 was also the end-of-support date for SharePoint Server 2016 and 2019. Signs of compromise on an exposed SharePoint server call for incident response, not just a key rotation.