Mark RadarMARK RADAR
About
EN
Sign in

Hackers Probe SharePoint Exploit Chain Uncovered With LLM Help

1 reports · First detected 2026-08-27 · Last active 2026-08-27

Microsoft SharePoint Server sits at the center of many corporate intranets, file-sharing systems and business workflows, often linking sensitive repositories with Active Directory. Rapid7 Labs researcher Stephen Fewer used publicly available large language models, with sustained guidance and verification from a security expert, to uncover CVE-2026-55040, an authentication bypass, and CVE-2026-63520, a remote-code-execution flaw. Chained together, the bugs can let an unauthenticated attacker run arbitrary code under the SharePoint site service account, making on-premises installations a high-value entry point.

Microsoft patched CVE-2026-55040 on July 14, 2026, and completed the chain’s remediation in its Aug. 11 security release with CVE-2026-63520, rated 8.1 under CVSS. After Rapid7 released proof-of-concept code for the authentication bypass on Aug. 11, Defused said its SharePoint honeypots recorded probes based on that code the following day. The observations indicate attempted exploitation, not necessarily successful compromise, but underscore how quickly public research can be weaponized. Administrators should install both the July and August SharePoint Server updates without delay.

All Coverage

1 original reports
ITHOME.COM.TW 2026-08-27
SharePoint攻擊鏈遭到利用

The Backstory

The history behind this event
Rapid7 Uses LLM to Uncover Critical SharePoint Exploit Chain2026-08-12 · 1 reports · similarity 0.89

Microsoft SharePoint is widely used by companies and government agencies to manage documents and internal collaboration, making server-side flaws a potentially valuable entry point into corporate networks. Cybersecurity firm Rapid7 used a large language model, or LLM, to help identify an exploit chain capable of bypassing authentication and achieving remote code execution, underscoring AI’s expanding role in vulnerability research.

Rapid7 said two SharePoint security flaws could be chained to let an unauthenticated attacker remotely execute arbitrary code on a vulnerable server. Microsoft has confirmed the critical exploit path and is rolling out security updates. Organizations operating on-premises SharePoint servers should apply the relevant patches promptly, as successful exploitation could give attackers control of the affected system and expose connected data and services.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)