Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Summary
Researchers discovered a critical vulnerability chain in Microsoft SharePoint on-premises servers that allows attackers without valid credentials to gain administrative access and run malicious code. The flaw was found partly through an AI agent that performed automated code analysis, chaining together two vulnerabilities (CVE-2026-55040 with CVSS 9.1 and CVE-2026-63520 with CVSS 8.1, a rating system measuring vulnerability severity) in SharePoint's authentication and service systems. The attack affects SharePoint Server Subscription Edition, 2019, and 2016, but not the cloud-based SharePoint Online.
Solution / Mitigation
Anyone running SharePoint on-premises should confirm the July update is installed, which breaks the vulnerability chain. The July fixes are: Subscription Edition KB5002882 (build 16.0.19725.20434), SharePoint Server 2019 KB5002883 (build 16.0.10417.20175), and SharePoint Server 2016 KB5002891 (build 16.0.5561.1001). Customers should also apply the August update when it appears, which fixes the second vulnerability (CVE-2026-63520).
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html
First tracked: August 11, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 75%