an AI spent 24 days hacking SharePoint. it found a way in that needs zero login

Rapid7 pointed an agentic AI at Microsoft's code for 120 hours across 24 days — and it built the same kind of exploit chain nation-state hackers…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-63520 is a CVSS 8.1 remote code execution bug in SharePoint's Business Connectivity Services, patched by Microsoft on August 12, 2026.

The short version

Chained with CVE-2026-55040 (a JWT auth bypass disclosed in July), it lets an attacker impersonate any user, including an admin, with zero valid login.

The short version

Rapid7 researcher Stephen Fewer found it with an AI-assisted workflow: 120 hours of agent runtime, 96 sessions, roughly 80,000 tool calls, across 24 days.

The short version

Every supported on-premises SharePoint version is affected: Subscription Edition, Server 2019, Enterprise Server 2016, plus Project Server and Office Web Apps Server.

The short version

Five KB patches are already out — 5002893, 5002894, 5002896, 5002905, 5002906.

My take

The actual headline isn't 'SharePoint has another RCE' — SharePoint has had plenty, including the ToolShell mess last year. It's that offensive security research just got a real speed multiplier,…

Aliteq

Read the full story

an AI spent 24 days hacking SharePoint. it found a way in that needs zero login

Read the full story on Aliteq