6 min read
Vulnerabilities Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
Microsoft's July 2026 Patch Tuesday dropped patches for 570+ vulnerabilities, with two actively exploited. The bigger story: AI is making Microsoft's own exploitability ratings meaningless.