CYBERSECURITYTRACKER
TRACKING7,665 stories in this site build1,646 vulnerability news stories in this site build
Permanent story citation

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4233

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 Labs disclosed CVE-2026-63520, a remote code execution vulnerability in Microsoft SharePoint with a CVSS score of 8.1 that stems from unsafe .NET type instantiation in Business Connectivity Services. The vulnerability affects all supported versions of SharePoint, Project Server, and Office Web Apps Server, and when chained with the previously disclosed authentication bypass CVE-2026-55040, enables unauthenticated RCE. Microsoft has released patches across multiple products, with Rapid7 planning to publish full technical details within 30 days of disclosure.

Why it matters: SharePoint administrators and organizations running vulnerable versions must apply patches immediately, as this RCE can be exploited without authentication when combined with CVE-2026-55040, allowing attackers to execute arbitrary code with service account privileges and access sensitive business data stored in SharePoint repositories.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 Labs disclosed CVE-2026-63520, a remote code execution vulnerability in Microsoft SharePoint with a CVSS score of 8.1 that stems from unsafe .NET type instantiation in Business Connectivity Services. The vulnerability affects all supported versions of SharePoint, Project Server, and Office Web Apps Server, and when chained with the previously disclosed authentication bypass CVE-2026-55040, enables unauthenticated RCE. Microsoft has released patches across multiple products, with Rapid7 planning to publish full technical details within 30 days of disclosure.

Why it matters: SharePoint administrators and organizations running vulnerable versions must apply patches immediately, as this RCE can be exploited without authentication when combined with CVE-2026-55040, allowing attackers to execute arbitrary code with service account privileges and access sensitive business data stored in SharePoint repositories.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary