SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.
Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

Key points
- Microsoft patched CVE-2026-55040, a critical SharePoint Server flaw rated 9.1 out of 10 on the industry severity scale.
- The bug lets an attacker with no account sign in as any user, including a full administrator.
- Affected products are SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.
- Researchers say an AI agent helped find and chain the underlying bugs together.
- Administrators should apply the November security update immediately, as public technical detail is now circulating.
Security researchers have disclosed a serious flaw in Microsoft SharePoint that lets an outsider walk into a company's document server as any user they choose, including the top administrator, without needing a valid account or password.
The bug is tracked as CVE-2026-55040 and carries a severity score of 9.1 on the standard 0 to 10 scale. Microsoft has issued a fix. The disclosure was first reported by The Hacker News.
SharePoint is the software many organisations use to store internal files, share documents between staff and run intranets. A break-in usually means access to sensitive records: contracts, HR files, board papers, source code.
The disclosure is also notable for how it was found. An AI agent, a piece of software that reasons through code autonomously, assisted researchers in spotting and connecting the underlying bugs. We first covered AI-assisted vulnerability research on 30 June 2026; this is only the second such story we've filed.
Which SharePoint versions are affected?
Three on-premises editions are in scope. If your organisation runs any of them, treat this as urgent.
| Product | Status |
|---|---|
| SharePoint Server Subscription Edition | Patch available |
| SharePoint Server 2019 | Patch available |
| SharePoint Server 2016 | Patch available |
SharePoint Online, the cloud-hosted version Microsoft runs itself, is not listed as affected. Customers on that service don't need to act.
What can an attacker actually do?
Quite a lot. The flaw is what the industry calls an authentication bypass: the checks that decide who you are can be tricked into accepting a request as someone else entirely.
Because the attacker can pick which user to impersonate, they can present themselves as a site administrator. From there they can read or delete anything the server holds, plant malicious files for staff to open, or use SharePoint as a stepping stone deeper into the corporate network. No password is required, and no phishing email needs to land first.
How urgent is the patch?
Very. As we reported on 17 July 2026, a patched SharePoint flaw was actively exploited within days of disclosure, with CISA giving US federal agencies just three days to apply the fix. Once technical write-ups circulate, opportunistic scanning tends to follow within hours.
Security teams should apply Microsoft's November security update for each affected edition, check server logs for unexpected admin logins or new privileged accounts created recently, and confirm that SharePoint backups are intact and stored offline. Restrict server access to the internal network or VPN where possible rather than leaving it exposed to the open internet.
What does this mean for the wider disclosure debate?
An AI agent doing part of the analytical work shortens the window defenders have between a product shipping and a serious flaw surfacing. Regulators watching how AI is used in both offence and defence will take note. That's the thing to watch here: not just this patch, but whether the pace of AI-assisted discovery starts outrunning the patch cycle in a measurable way.
For now, patch SharePoint. Then check who has been logging in.
Common questions
Do I need to do anything as an ordinary SharePoint user?
No direct action is needed. Your IT team applies the fix on the server. If you're asked to sign in again after an update, that's normal.
Is SharePoint Online affected?
No. The flaw affects the on-premises SharePoint Server editions listed above, not the cloud service Microsoft operates.



