Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Summary
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.