SharePoint RCE: AI-Discovered Exploit Chain (CVE-2026-55040, CVE-2026-63520)
A JWT authentication bypass and a remote code execution vulnerability in Microsoft SharePoint, chained together, give an attacker full control of a vulnerable server with zero credentials. Tracked as CVE-2026-55040 and CVE-2026-63520, the pair was discovered and weaponized by Rapid7 Labs. The goal was to test whether an AI agent, guided by human researchers, could find and weaponize a real exploit chain. It could.