Security researchers disclosed an unauthenticated remote code execution vulnerability in Microsoft SharePoint that chains multiple flaws to grant attackers full administrative access without valid credentials. The vulnerability, tracked as CVE-2026-55040 with a CVSS score of 9.1, affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.

The exploit chain enables attackers to enter affected SharePoint instances as any user, including administrators, bypassing authentication requirements entirely. This grants attackers the ability to execute arbitrary code on vulnerable servers with no need for legitimate access or credentials. The research team leveraged AI agents during the vulnerability discovery process, demonstrating how machine learning tools can identify complex attack chains that combine multiple weaknesses into a single, devastating exploit path.

SharePoint Server deployments remain common in enterprise environments where organizations host document collaboration, intranet portals, and business-critical workflows. An unauthenticated RCE vulnerability of this severity poses immediate risk to affected organizations. Attackers exploiting CVE-2026-55040 could compromise entire SharePoint infrastructure, steal sensitive documents, modify business-critical data, or pivot deeper into corporate networks.

The affected versions span legacy and current deployments. SharePoint Server 2016 reached extended support status but remains widely deployed. SharePoint Server 2019 continues in mainstream support. SharePoint Server Subscription Edition represents the current on-premises offering. Organizations running any of these versions face direct exposure.

Microsoft has released patches addressing this vulnerability. Organizations should prioritize deploying these updates immediately across all affected SharePoint instances. The use of AI agents in identifying this exploit chain reflects a broader trend in security research where machine learning tools accelerate the discovery of complex vulnerability chains that traditional manual analysis might miss. This capability underscores the need for defenders to adopt similar advanced detection methods.

Immediate action is required