CVE Tools

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

The Hacker NewsBy The Hacker News

PoC publicSharePoint

Our summary

Rapid7 has disclosed a public proof-of-concept exploit chain that allows unauthenticated remote attackers to achieve code execution on Microsoft SharePoint servers. The attack leverages CVE-2026-55040, a critical JWT authentication bypass, combined with CVE-2026-63520, an unsafe .NET type instantiation flaw in Business Connectivity Services. These vulnerabilities affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Notably, the discovery of this chain was facilitated by an AI agent during rapid research sprints. Organizations should apply the July updates, specifically KB5002882, KB5002883, and KB5002891, to mitigate this risk.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store