PoC public SharePoint ai-ml Rapid7 auth-bypass
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
CVE Tools coverage
Rapid7 has disclosed a public proof-of-concept exploit chain that allows unauthenticated remote attackers to achieve code execution on Microsoft SharePoint servers. The attack leverages CVE-2026-55040, a critical JWT authentication bypass, combined with CVE-2026-63520, an unsafe .NET type instantiation flaw in Business Connectivity Services. These vulnerabilities affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Notably, the discovery of this chain was facilitated by an AI agent during rapid research sprints. Organizations should apply the July updates, specifically KB5002882, KB5002883, and KB5002891, to mitigate this risk.