Stephen Fewer
Earlier this year I built out an unauth RCE chain against SharePoint, we disclosed it to Microsoft in May and today they have patched out the chains auth bypass vuln, CVE-2026-55040. Disclosure details on the @rapid7 blog, full technical details to be published at a later date...
Rapid7
In conducting a 0-day research project against #SharePoint, Rapid7 Labs discovered 2 new vulns that, when chained together, achieve RCE against a vulnerable server. Today, Rapid7 and Microsoft are disclosing CVE-2026-55040 – the first vuln in this chain: https://r-7.co/4f2HpQO