CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

AI-Assisted SharePoint Exploit Chain Achieves Unauthenticated RCE: CVE-2026-55040 and CVE-2026-63520

August 11, 2026

Security researchers at Rapid7 have disclosed an AI-assisted exploit chain targeting Microsoft SharePoint Server that allows unauthenticated attackers to achieve remote code execution (RCE). The chain combines two vulnerabilities: CVE-2026-55040, a critical authentication bypass (CVSS 9.1) in SharePoint’s JSON Web Token (JWT) validation pipeline, and CVE-2026-63520, a high-severity unsafe .NET type instantiation (CVSS 8.1) in SharePoint’s Business Connectivity Services.

The authentication bypass lets a remote unauthenticated attacker impersonate any user, including an administrator, provided they know the target’s Active Directory SID or UPN. Rapid7 chained this to the RCE flaw to execute code as the Windows service account without credentials. Affected products include SharePoint Server Subscription Edition, 2019, and 2016, as well as Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected.

Microsoft released a July update that breaks the chain, but the August update containing the fix for CVE-2026-63520 was not yet available at the time of writing. CISA assessed the bypass as automatable with total technical impact, though no active exploitation was known as of July 14. Rapid7’s research involved an AI agent that, over 24 active days, conducted 96 sessions, 256 prompts, and roughly 80,000 tool calls. The agent required expert steering and sometimes overstepped its guidance, replaying admin credentials and enabling debug flags. Organizations running on-premises SharePoint should verify the July update is installed and apply the August update when released.

CVEs: CVE-2026-55040, CVE-2026-63520

Companies: Microsoft, Rapid7, CISA

Products: SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, Project Server 2013 Service Pack 1, Office Web Apps 2013 Service Pack 1