AI-Assisted SharePoint Hack: CVE-2026-55040 & 63520 Unauthenticated RCE Explained (2026)

Microsoft SharePoint servers have been found vulnerable to a critical security flaw, allowing unauthenticated remote code execution (RCE) by attackers. This exploit chain, tracked as CVE-2026-55040, affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016, but not SharePoint Online. The vulnerability enables attackers to assume the identity of any chosen user, including administrators, by leveraging a flaw in SharePoint's JSON Web Token (JWT) validation pipeline. This pipeline issue, combined with a separate RCE flaw (CVE-2026-63520), allows attackers to run code on the server as the Windows service account. The exploit chain was partially automated using an AI agent, which, despite initial challenges, eventually led to the discovery of the vulnerabilities. Microsoft has released a fix in July, but the update history does not list an August package, indicating that the build numbers carrying the fix are not yet public. It is crucial for organizations running SharePoint on-premises to confirm the July update and apply the August update when available. The vulnerability was not yet known to have been exploited as of July 14, according to CISA. However, the situation highlights the importance of prompt patching and the need for organizations to stay vigilant against emerging threats. The incident also underscores the potential risks associated with unsupported versions of SharePoint, which may not receive future security updates. Additionally, CISA has issued an alert regarding three other SharePoint flaws under active exploitation, emphasizing the need for organizations to take immediate action to protect their systems.

AI-Assisted SharePoint Hack: CVE-2026-55040 & 63520 Unauthenticated RCE Explained (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Jonah Leffler

Last Updated:

Views: 5497

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.