Home / Aug 12, 2026 / Story
0
#5 The Hacker News general August 11, 2026 at 16:47 UTC

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

By [email protected] (The Hacker News)

AI Summary

Researchers disclosed CVE-2026-55040 (CVSS 9.1), an unauthenticated RCE vulnerability affecting Microsoft SharePoint Server Subscription Edition, 2019, and 2016, which was partially discovered using an AI agent. CISA has since confirmed (article 7434) that ransomware gangs are actively exploiting a related SharePoint RCE flaw flagged since early July, making immediate patching of all SharePoint Server deployments critical for defenders.

Relevance score: 85.0/100

# More from August 12