Threat Intelligence

AI-Discovered Flaw Lets Attackers Break Into Microsoft SharePoint Without a Password

The Hacker News · 12 Aug 2026
Key Takeaway If your business runs SharePoint Server, check for and apply Microsoft's security updates immediately, as this flaw allows attackers to bypass login credentials entirely.

Security researchers have disclosed a serious vulnerability in Microsoft SharePoint that allows attackers to gain access as any user—including an administrator—without needing a valid account. Notably, much of the work behind discovering this exploit chain was carried out with the help of an AI agent, highlighting how artificial intelligence is increasingly being used to find complex security flaws.

The vulnerability, tracked as CVE-2026-55040, carries a severity score of 9.1 out of 10, making it a critical issue. It affects several widely used versions of SharePoint, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Because SharePoint is commonly used by businesses to store and share internal documents, a successful attack could give hackers unauthorised access to sensitive company data without needing to steal a password first.

While Microsoft's response and patch details were not fully outlined in the available report, the severity of this flaw means organisations running affected SharePoint versions should treat this as a high-priority issue. As AI tools make it easier for both defenders and attackers to identify vulnerabilities, businesses need to stay alert and ensure their systems are kept up to date.

SharePoint Critical Vulnerability AI Security Microsoft RCE
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.