What it is
This profile covers Rapid7 Labs’ agentic vulnerability-research workflow rather than a named commercial product. Rapid7 describes repeated research sprints using public models, a heavily prompted agent, reverse engineering, and manual researcher direction against Microsoft SharePoint.
What is verified
Rapid7 says the successful sprint yielded a two-vulnerability chain providing unauthenticated remote code execution. It reports 24 active agent days, 96 sessions, 256 prompts, and approximately 80,000 tool calls. Microsoft accepted and fixed CVE-2026-55040 and CVE-2026-63520.
The AI role remains self-reported because Microsoft credits Rapid7 and the human reporter rather than naming a specific agent or model.