THREATOPS
THREAT OPSThreat News › Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

medthehackernewsPublished 2026-08-11

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.

The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html