CyberNews
← Back to dashboard
NEWS The Hacker News CVE-2026-55040

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Aug 11, 2026, 04:47 PM · by The Hacker News

Authoritative NVD/CISA vulnerability data (read-only)

CVE-2026-55040

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.

The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

Source: The Hacker News