Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Read original article ↗AI Summary
Researchers at Rapid7 discovered an exploit chain enabling unauthenticated remote code execution (RCE) on on-premises Microsoft SharePoint servers. The chain begins with CVE-2026-55040, a vulnerability in SharePoint's JWT validation pipeline that allows an unauthenticated attacker to impersonate any user given their SID or UPN. This is combined with CVE-2026-63520, an unsafe .NET type instantiation in Business Connectivity Services, to achieve RCE as the server's Windows service account. The attack affects SharePoint Server Subscription Edition, 2019, and 2016, as well as Project Server 2013 SP1 and Office Web Apps 2013 SP1. The July 2026 updates reportedly break the exploit chain, though the August patch containing the fix had not yet been publicly released at the time of disclosure.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.