SECURITY·중요도 9·2026. 08. 11.·The Hacker News

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

── KO ──────────────────

AI를 활용한 SharePoint 취약점이 확인되었습니다.

보안 연구원들이 유효한 계정 없이도 Microsoft SharePoint 서버에 접근할 수 있는 방법을 발견했습니다. 이 취약점은 CVE-2026-55040으로 추적되며, SharePoint Server Subscription Edition, 2019 및 2016 버전에 영향을 미칩니다. AI 에이전트를 사용하여 취약점을 발견한 것이 주요한 요소입니다.


── EN ──────────────────

An AI-assisted vulnerability in SharePoint allows unauthorized access.

Security researchers have discovered a method to access Microsoft SharePoint servers, including administrative rights, without a valid account. This flaw, tracked as CVE-2026-55040, affects SharePoint Server Subscription Edition, as well as the 2019 and 2016 versions. A significant portion of the discovery process was conducted using an AI agent.

원문 보기 →목록으로