Search
Find merged stories by title or summary.
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Microsoft SharePoint RCE Flaw Chains Allow Unauthenticated Server Takeover
A newly disclosed Microsoft SharePoint Server vulnerability is raising urgent concerns for enterprise defenders after researchers demonstrated how it can be combined with an earlier flaw to enable unauthenticated remote code execution (RCE). Tracked as CVE-2026-63520, the issue was identified by Rapid7 Labs as part of a zero-day research initiative and has been coordinated with Microsoft. On its own, the vulnerability allows an unauthenticated remote attacker to execute code over the network under specific conditions. More significantly, researchers said it forms the second stage of an exploit chain with CVE-2026-55040, a SharePoint vulnerability disclosed in July 2026 .
CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to disclosure. ⠀ CVE-2026-63520 affects all supported versions of Microsoft SharePoint, and certain versions of Microsoft Project Server and Microsoft Office Web Apps Server. For the purpose of our research, we focused solely on SharePoint.
You've reached the end of current stories for this search.
