6 min read
Vulnerabilities Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
Rapid7 used a heavily supervised AI agent to find a JWT forgery flaw and an unsafe .NET deserialization bug in SharePoint, chaining them into unauthenticated RCE. CVE-2026-55040 is now under active attack.
CVE-2026-47729 (Squidbleed) is a heap buffer overread in Squid Proxy's FTP parser, present since 1997, discovered by Anthropic's Claude Mythos Preview: it leaks users' HTTP credentials and session tokens in corporate and shared proxy environments.