KEVIntel captured telemetry data revealing 12 exploitation attempts targeting CVE-2026-55040 since July 19, 2026. Eight of these attempts occurred on August 12-13, 2026, following the release of a public PoC. The attempts originated from eight unique IP addresses across five countries, indicating widespread attacker interest.