Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Researchers disclosed an AI-assisted exploit chain for Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS 9.1), that allows unauthenticated attackers to achieve remote code execution and impersonate any user, including administrators. The flaw affects SharePoint Server Subscription Edition, 2019, and 2016.
Security researchers uncovered an exploit chain allowing unauthenticated remote code execution on Microsoft SharePoint servers, enabling attackers to impersonate any user—including administrators—without valid credentials. The discovery was significantly aided by an AI agent. Tracked as CVE-2026-55040 with a CVSS score of 9.1, the flaw impacts SharePoint Server Subscription Edition, 2019, and 2016. Microsoft has released a security update to address the vulnerability.