Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
PoC publicSharePointOur summary
Rapid7 has disclosed a public proof-of-concept exploit chain that allows unauthenticated remote attackers to achieve code execution on Microsoft SharePoint servers. The attack leverages CVE-2026-55040, a critical JWT authentication bypass, combined with CVE-2026-63520, an unsafe .NET type instantiation flaw in Business Connectivity Services. These vulnerabilities affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Notably, the discovery of this chain was facilitated by an AI agent during rapid research sprints. Organizations should apply the July updates, specifically KB5002882, KB5002883, and KB5002891, to mitigate this risk.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.