AI-Assisted Exploit Chain Disclosed for Microsoft SharePoint, Allowing Unauthenticated Remote Code Execution

Security researchers have revealed an exploit chain for Microsoft SharePoint servers, tracked as CVE-2026-55040 (CVSS 9.1) and CVE-2026-63520 (CVSS 8.1), that enables unauthenticated remote code execution. A significant portion of the discovery work was performed by an AI agent. The flaws affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, allowing attackers to assume a chosen user's identity and run code on the server without credentials.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai