ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Repair Hacked Website
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

SharePoint Server Critical Flaw: Immediate Steps to Secure Your Farm

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. SharePoint Server Critical Flaw: Immediate St...
  • All articles
  • Categories
  • Tags
  • Statuses

SharePoint Server Critical Flaw: Immediate Steps to Secure Your Farm

Critical SharePoint Vulnerability Under Active AttackIn August 2026, organizations running Microsoft SharePoint Server on-premises face a pressing sec...

Critical SharePoint Vulnerability Under Active Attack

In August 2026, organizations running Microsoft SharePoint Server on-premises face a pressing security challenge. A critical vulnerability, tracked as CVE-2026-55040, is being actively exploited in the wild. This flaw, rated 9.1 on the CVSS scale, allows remote attackers to bypass authentication and gain unauthorized access to SharePoint sites. The urgency escalates because a public proof-of-concept (PoC) was released shortly after Microsoft's July 2026 Patch Tuesday, giving malicious actors a ready-made exploit.

Server cabinet with red warning light and holographic shield protecting it

SharePoint Server is a cornerstone of many enterprises, housing sensitive documents, workflows, and collaboration tools. A successful attack can lead to data theft, privilege escalation, and lateral movement within the network. For system administrators and IT teams in Spain, particularly those managing servers in Barcelona, Madrid, or Lleida, understanding and mitigating this risk is now a top priority.

Understanding the Flaw and Its Impact

The vulnerability stems from weaknesses in the validation pipeline of JWT tokens. In practical terms, an attacker can forge or manipulate tokens to impersonate any user, including administrators, without needing valid credentials. This means they can modify configurations, access restricted content, and alter permissions—actions typically reserved for authorized personnel.

The affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. The risk is particularly high for instances exposed to the internet, as the attack vector is remote and requires no prior authentication. Moreover, this bypass can be chained with other vulnerabilities or misconfigurations to amplify the damage, potentially compromising the entire server farm.

Immediate Mitigation Steps

First and foremost, apply the official security updates released by Microsoft in July 2026 to every node in your SharePoint farm. Verify that the build is fully patched, as incomplete updates may leave residual exposure. Prioritize servers that are accessible from the internet, as they are the most likely targets.

While remediation is underway, reduce the attack surface by restricting external access to SharePoint. If possible, place the service behind a VPN or firewall, limiting exposure to trusted IP ranges. This temporary measure can significantly lower the risk of exploitation.

Detecting Signs of Compromise

After patching, shift focus to detecting any prior compromise. Review IIS logs and SharePoint telemetry for suspicious activities, such as unusual login patterns, impersonation attempts, or unexpected administrative actions. Look for anomalies in privileged account usage and investigate any deviations from normal behavior.

Strengthen monitoring and alerting on accounts with elevated privileges. Implement a robust incident response plan that includes credential rotation for all users, especially those with administrative access. Check for signs of persistence, such as new scheduled tasks, modified registry keys, or unauthorized service accounts. In severe cases, consider a clean reinstallation of affected servers to ensure no backdoors remain.

Proactive Security for Your Infrastructure

This incident underscores the importance of a proactive, layered security strategy. For organizations managing multiple servers, centralizing protection can be a game-changer. Solutions that aggregate threat intelligence and automate blocking of malicious IPs across all machines can significantly reduce the window of exposure. By sharing reputation feeds among servers, you can quickly neutralize threats that target one system before they spread to others.

At ALMC.es, we understand the complexities of server security. Our Abuse Shield service centralizes protection for your servers, offering automated blocking of malicious IPs, managed fail2ban across multiple machines, and a shared reputation feed. This approach not only simplifies administration but also ensures that a threat detected on one server is immediately blocked on all others, providing a unified defense.

In the current threat landscape, relying on manual patching and isolated defenses is no longer sufficient. By adopting a centralized security solution, you can respond faster to emerging threats like CVE-2026-55040 and maintain the integrity of your infrastructure.

Conclusion

CVE-2026-55040 is a stark reminder that on-premises systems require constant vigilance. The active exploitation and public PoC demand immediate action. Apply patches, reduce exposure, and scrutinize your logs for signs of intrusion. For long-term resilience, consider integrating a centralized protection platform that automates threat response and fosters a collaborative defense across your entire server estate.

Don't wait for the next vulnerability to catch you off guard. Evaluate your security posture today and take steps to safeguard your SharePoint environment and beyond.

Related

  • GeoServer RCE: Critical Flaw CVE-2024-36401 Under Active Attack
  • Zimbra CVE-2026-73570: Patch Now, Then Hunt for Intrusions
  • Keycloak Critical Flaw: Force Password Reset and Account Takeover Risk
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Process Automation (Scripts and Bots)
API Integrations & Microservices
System & Server Hardening
Cloud Security (AWS, Azure, Google Cloud)
Performance Optimization
Relacionados
  • GeoServer CVE-2024-36401: Act Fast to Shield Your Servers
    Cybersecurity · 58 minutes ago
  • VMware vCenter CVE-2026-59310: Urgent Patch Guide for EU Admins
    Cybersecurity · 58 minutes ago
  • Guard Your Code: The GhostSplice MCP Attack and How to Stay Safe
    Cybersecurity · 58 minutes ago
  • CISA KEV Update: Six Actively Exploited Flaws Including NetScaler, Linux, SQL Server
    Cybersecurity · 1 hour ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 1 hour ago
  • SLEEPWALKER Backdoor: A Stealthy Threat for Windows Servers
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • GXtract
    Development
  • CodeSeeker
    Development
  • PentestGPT-MCP
    Development
  • RSS MCP Server by CData
    Communication
  • Linear MCP Server
    Productivity
  • Airtable User MCP
    Database
  • AIO-MCP Server
    Development
  • godoc-mcp-server
    Development
  • Pickapicon
    Development
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar