SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.

Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial image of a dimly lit server room with rack-mounted enterprise servers, one status LED glowing amber, subtle blue ambient light, focus on cab
Share

Key points

  • Microsoft patched CVE-2026-55040, a critical SharePoint Server flaw rated 9.1 out of 10 on the industry severity scale.
  • The bug lets an attacker with no account sign in as any user, including a full administrator.
  • Affected products are SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.
  • Researchers say an AI agent helped find and chain the underlying bugs together.
  • Administrators should apply the November security update immediately, as public technical detail is now circulating.

Security researchers have disclosed a serious flaw in Microsoft SharePoint that lets an outsider walk into a company's document server as any user they choose, including the top administrator, without needing a valid account or password.

The bug is tracked as CVE-2026-55040 and carries a severity score of 9.1 on the standard 0 to 10 scale used by security teams. Microsoft has issued a fix.

SharePoint is the software many organisations use to store internal files, run intranets and share documents between staff. A break-in on that server usually means access to sensitive records: contracts, HR files, board papers, source code.

The disclosure, first reported by The Hacker News, is also notable for how it was found. Part of the analysis was carried out by an AI agent, a piece of software that reasons through code on its own, which the researchers used to spot and connect the underlying bugs.

Which SharePoint versions are affected?

Three on-premises editions are in scope. If your organisation runs any of them, treat this as urgent.

Product Status
SharePoint Server Subscription Edition Patch available
SharePoint Server 2019 Patch available
SharePoint Server 2016 Patch available

SharePoint Online, the cloud-hosted version Microsoft runs itself, is not listed as affected. Customers on that service do not need to act.

What can an attacker actually do?

A lot. The flaw is what the industry calls an authentication bypass, meaning the checks that decide who you are can be tricked into accepting a request as someone else.

Because the attacker can pick which user to impersonate, they can present themselves as a site administrator. From there they can read, change or delete anything the server holds, plant malicious files for staff to open, or use SharePoint as a stepping stone deeper into the corporate network.

No password is needed. No phishing email is needed. The attacker only needs to reach the server over the network.

How urgent is the patch?

Very. SharePoint has been a favourite target this year, with earlier flaws exploited in the wild within days of disclosure. Once technical write-ups appear, opportunistic scanning tends to follow within hours.

Security teams should:

  • Apply Microsoft's November security update for each affected SharePoint edition.
  • Check server logs for unexpected admin logins or new privileged accounts created in the past several weeks.
  • Restrict SharePoint server access to the internal network or VPN where possible, rather than exposing it to the open internet.
  • Confirm that backups of SharePoint content are intact and offline.

What does this mean for the wider disclosure debate?

The involvement of an AI agent in finding the bug chain will draw attention from regulators watching how AI is used in both offence and defence. The pattern here, human researchers guiding an AI through complex code, is becoming common, and it shortens the window defenders have between a product shipping and a serious flaw surfacing.

For now, the practical message is simple. Patch SharePoint. Then check who has been logging in.

Common questions

Do I need to do anything as an ordinary SharePoint user?

No direct action. Your IT team applies the fix on the server. If you are asked to sign in again after an update, that is normal.

Is Microsoft 365 or SharePoint Online affected?

No. The flaw affects the on-premises SharePoint Server editions listed above, not the cloud service Microsoft operates.

© 2026 Threat Vectr