Story thread · 3 reports / 2 sources
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
thehackernews.com · 3h

How the coverage leans
Across 2 sources · syndicated copies counted once
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's
First report: CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — bleepingcomputer.com, 1d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.