🔴 Critical  |  Source: The Hacker News


A critical vulnerability in Microsoft SharePoint Server (CVE-2026-55040, CVSS 9.1) allows attackers to impersonate any user, including administrators, without needing valid credentials, ultimately enabling unauthenticated remote code execution. The exploit chain was discovered with significant assistance from an AI agent, marking a notable development in AI-assisted vulnerability research. Affected versions include SharePoint Server Subscription Edition, 2019, and 2016.

Security Architect’s Take: Prioritise emergency patching of all on-premises SharePoint Server instances (Subscription Edition, 2019, 2016) immediately; if patching cannot be completed within 24–48 hours, consider isolating SharePoint servers from internet exposure and enforcing network-level access controls to reduce attack surface whilst remediation is under way.

Original advisory: Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE