CVE Tools

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 BlogBy Stephen Fewer7 min read

PoC publicSharePoint

Our summary

Rapid7 Labs has disclosed a remote code execution vulnerability, CVE-2026-63520, affecting Microsoft SharePoint, Project Server, and Office Web Apps Server. A public proof-of-concept is now available, revealing that an unsafe .NET type instantiation flaw in Business Connectivity Services allows attackers to execute arbitrary commands with service account privileges. Although rated High (CVSS 8.1), the issue becomes critical when chained with the previously disclosed authentication bypass CVE-2026-55040, enabling fully unauthenticated attacks. Microsoft has released fixes for this flaw, and administrators are urged to apply the latest updates to secure their environments.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store