Hackers Probe SharePoint Exploit Chain Uncovered With LLM Help
Microsoft SharePoint Server sits at the center of many corporate intranets, file-sharing systems and business workflows, often linking sensitive repositories with Active Directory. Rapid7 Labs researcher Stephen Fewer used publicly available large language models, with sustained guidance and verification from a security expert, to uncover CVE-2026-55040, an authentication bypass, and CVE-2026-63520, a remote-code-execution flaw. Chained together, the bugs can let an unauthenticated attacker run arbitrary code under the SharePoint site service account, making on-premises installations a high-value entry point.
Microsoft patched CVE-2026-55040 on July 14, 2026, and completed the chain’s remediation in its Aug. 11 security release with CVE-2026-63520, rated 8.1 under CVSS. After Rapid7 released proof-of-concept code for the authentication bypass on Aug. 11, Defused said its SharePoint honeypots recorded probes based on that code the following day. The observations indicate attempted exploitation, not necessarily successful compromise, but underscore how quickly public research can be weaponized. Administrators should install both the July and August SharePoint Server updates without delay.
All Coverage
1 original reportsThe Backstory
The history behind this eventRapid7 Uses LLM to Uncover Critical SharePoint Exploit Chain
Microsoft SharePoint is widely used by companies and government agencies to manage documents and internal collaboration, making server-side flaws a potentially valuable entry point into corporate networks. Cybersecurity firm Rapid7 used a large language model, or LLM, to help identify an exploit chain capable of bypassing authentication and achieving remote code execution, underscoring AI’s expanding role in vulnerability research.
Rapid7 said two SharePoint security flaws could be chained to let an unauthenticated attacker remotely execute arbitrary code on a vulnerable server. Microsoft has confirmed the critical exploit path and is rolling out security updates. Organizations operating on-premises SharePoint servers should apply the relevant patches promptly, as successful exploitation could give attackers control of the affected system and expose connected data and services.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →