EventCybersecurityAugust 11, 2026

AI-assisted exploit chain reaches unauthenticated RCE on SharePoint

Rapid7 chained CVE-2026-55040 (CVSS 9.1), an auth bypass in SharePoint's JWT pipeline, with CVE-2026-63520 (CVSS 8.1) for unauthenticated RCE; an AI agent did much of the discovery. Affects SharePoint Server Subscription Edition, 2019, and 2016, not SharePoint Online. CISA says the bypass wasn't known exploited as of July 14.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed