[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQaU_pu6SyAU7Wysrhzn5S3TJZebBq1DAYaTN3SAM14Y":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"ecb25cf7-2817-4df2-8a38-c285d67fc3aa","Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE","researchers-disclose-ai-assisted-sharepoint-exploit-chain-reaching-unauthenticat-83f9b7","Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's","Security researchers have disclosed a critical vulnerability chain affecting multiple on-premises versions of Microsoft SharePoint, allowing unauthenticated attackers to gain administrator access. The exploit chain, facilitated by an AI agent during the research process, leverages two flaws: CVE-2026-55040 for identity bypass and CVE-2026-63520 for remote code execution. While Microsoft has released patches, the end-of-support status for some affected versions raises concerns about ongoing security.","Researchers disclose AI-assisted exploit chain for unauthenticated RCE in Microsoft SharePoint.","Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Swati KhandelwalAug 11, 2026Vulnerability \u002F Enterprise Security Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them. It lets a remote unauthenticated attacker assume a chosen user's identity. The attack has one prerequisite: the intruder has to know which account they want to become, either by its Active Directory security identifier (SID) or its user principal name (UPN), which is formatted like an email address. Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials. Microsoft and the firm disclosed that second flaw on August 11 as CVE-2026-63520 (CVSS 8.1), an unsafe .NET type instantiation in SharePoint's Business Connectivity Services. Exploiting it runs attacker code as the Windows service account behind the site. It reaches further than the bypass: Subscription Edition, 2019, and 2016 are all affected, along with Project Server 2013 Service Pack 1 and Office Web Apps 2013 Service Pack 1. Rapid7 says the flaw is fixed, but Microsoft's SharePoint update history listed no August package for any edition at the time of writing, so the build numbers carrying that fix are not yet public. Anyone running SharePoint on-premises should confirm the July update is installed, which Rapid7 says breaks the chain, and apply the August update when it appears. CISA said on July 14 that the bypass was not yet known to have been exploited. The bypass sits in SharePoint's JSON Web Token (JWT) validation pipeline. Rapid7 says several issues in that pipeline let an unauthenticated attacker act as the target user. Its proof-of-concept queries the target's domain controller to enumerate users by SID, then uses the bypass until it identifies the site administrator. In that demonstration, the prerequisite was less of a barrier than it sounds. CISA's assessment of the flaw, filed to the National Vulnerability Database on July 14, marks the attack automatable and its technical impact total. The firm published its full technical analysis and a proof-of-concept script on August 11. Rapid7 ran two research sprints against the SharePoint codebase, in January and March 2026. January produced no usable chain. March did: the firm says a heavily prompted agent helped produce the two-vulnerability path. Across 24 active days of agentic work, Rapid7 recorded 96 sessions, 256 prompts, and roughly 80,000 tool calls. A fully automated approach would not have worked, the firm says, because the model too often produced findings that were questionable or inaccurate, and an expert had to steer the agent. The firm also says the agent cheated. It overstepped its guidance to reach the goal, replaying admin credentials, enabling debug flags, and reading secrets, none of which were in the original threat model. Microsoft shipped the July fix in three server updates: Subscription Edition KB5002882, build 16.0.19725.20434 SharePoint Server 2019 KB5002883, build 16.0.10417.20175 SharePoint Server 2016 KB5002891, build 16.0.5561.1001 July 14 was also the end-of-support date for SharePoint Server 2016 and 2019. Microsoft's lifecycle guidance says products past end of support receive no new security updates. Both are on the affected list for the newly disclosed RCE, and Rapid7 tells customers of affected products to install the latest update. Whether Microsoft ships one for the two versions it stopped supporting in July is unresolved. For those farms, the exposure that matters is what comes next. The July update is said to break this chain; flaws found from here on would not be fixed under the published lifecycle. Three other SharePoint flaws were under active exploitation when CISA published its July 14 alert. The agency said attackers were stealing IIS machine keys and urged organizations to hunt for and remove harvesting artifacts before rotating those keys. Signs of compromise on an exposed SharePoint server call for incident response, not just a key rotation. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Authentication, enterprise security, Identity Security, Microsoft, Patch Management, remote code execution, server security, Software Security, Vulnerability ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fresearchers-disclose-ai-assisted.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgbDSDTAbeeAZ8pykGFRAGcCDs_3LZBuD8tYUJfh0jG35r_o84zM_bNo7q3TWcoEMPmZqvhzucujEF72b2c2HnzfDjowsj4Iw4psQEwcgADR_rVMCXVw18arcpSB0WLblkZeypa-bgJPsD0qwrqBUk2umKezFZTtuDpbi_kQlsGUSiveb2suBMRyc3oZhQ\u002Fs1600\u002Fadmin.jpg","2026-08-11T16:47:44+00:00","2026-08-11T18:00:24.524264+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"SharePoint Server Subscription Edition","product",{"name":22,"type":20},"SharePoint Server 2019",{"name":24,"type":20},"SharePoint Server 2016",{"name":26,"type":20},"Project Server 2013 Service Pack 1",{"name":28,"type":20},"Office Web Apps 2013 Service Pack 1",{"name":30,"type":31},"Microsoft","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,40,45],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55],{"type":52,"value":53,"context":54},"cve","CVE-2026-55040","SharePoint identity bypass vulnerability",{"type":52,"value":56,"context":57},"CVE-2026-63520","SharePoint unsafe .NET type instantiation vulnerability"]