AI-Assisted Exploit Chain Disclosed for Microsoft SharePoint, Allowing Unauthenticated Remote Code Execution
Security researchers have revealed an exploit chain for Microsoft SharePoint servers, tracked as CVE-2026-55040 (CVSS 9.1) and CVE-2026-63520 (CVSS 8.1), that enables unauthenticated remote code execution. A significant portion of the discovery work was performed by an AI agent. The flaws affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, allowing attackers to assume a chosen user's identity and run code on the server without credentials.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai