< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-11T22:17:44+05:30

AI-Assisted Exploit Chain Enables Unauthenticated RCE in SharePoint Servers

Researchers discovered an AI-assisted exploit chain in SharePoint that allows unauthenticated remote code execution (RCE) by leveraging two vulnerabilities, CVE-2026-55040 and CVE-2026-63520, affecting multiple on-premises editions. The exploit requires knowledge of a target user's SID or UPN and chains a JWT validation bypass with a .NET type instantiation flaw, prompting urgent patching for affected systems.

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.

The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

Read original article

*** END OF TRANSMISSION ***