As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Rapid7 Labs disclosed CVE-2026-63520, a remote code execution vulnerability in Microsoft SharePoint with a CVSS score of 8.1 that stems from unsafe .NET type instantiation in Business Connectivity Services. The vulnerability affects all supported versions of SharePoint, Project Server, and Office Web Apps Server, and when chained with the previously disclosed authentication bypass CVE-2026-55040, enables unauthenticated RCE. Microsoft has released patches across multiple products, with Rapid7 planning to publish full technical details within 30 days of disclosure.
Why it matters: SharePoint administrators and organizations running vulnerable versions must apply patches immediately, as this RCE can be exploited without authentication when combined with CVE-2026-55040, allowing attackers to execute arbitrary code with service account privileges and access sensitive business data stored in SharePoint repositories.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Rapid7 Labs disclosed CVE-2026-63520, a remote code execution vulnerability in Microsoft SharePoint with a CVSS score of 8.1 that stems from unsafe .NET type instantiation in Business Connectivity Services. The vulnerability affects all supported versions of SharePoint, Project Server, and Office Web Apps Server, and when chained with the previously disclosed authentication bypass CVE-2026-55040, enables unauthenticated RCE. Microsoft has released patches across multiple products, with Rapid7 planning to publish full technical details within 30 days of disclosure.
Why it matters: SharePoint administrators and organizations running vulnerable versions must apply patches immediately, as this RCE can be exploited without authentication when combined with CVE-2026-55040, allowing attackers to execute arbitrary code with service account privileges and access sensitive business data stored in SharePoint repositories.
- Source published
- First seen by Cybersecurity Tracker