All systems

Rapid7 Labs Program

Rapid7 Labs Agentic Research Workflow

Rapid7 Labs' researcher-directed agentic workflow, publicly tied to a two-CVE SharePoint unauthenticated-RCE chain.

1
Indexed entries
2
CVE IDs tracked
1
Critical/high entries
88%
Evidence index

What it is

This profile covers Rapid7 Labs’ agentic vulnerability-research workflow rather than a named commercial product. Rapid7 describes repeated research sprints using public models, a heavily prompted agent, reverse engineering, and manual researcher direction against Microsoft SharePoint.

What is verified

Rapid7 says the successful sprint yielded a two-vulnerability chain providing unauthenticated remote code execution. It reports 24 active agent days, 96 sessions, 256 prompts, and approximately 80,000 tool calls. Microsoft accepted and fixed CVE-2026-55040 and CVE-2026-63520.

The AI role remains self-reported because Microsoft credits Rapid7 and the human reporter rather than naming a specific agent or model.

Sources

Attributed findings

Catalogued entries credited to Rapid7 Labs Agentic Research Workflow.