Microsoft SharePoint is vulnerable to a remote code execution exploit, identified as CVE-2026-63520, which can be triggered by chaining it with another vulnerability, CVE-2026-55040. The discovery of this exploit is a result of a zero-day research project conducted by Rapid7 Labs, and both Rapid7 and Microsoft have disclosed the RCE vulnerability. The first vulnerability in the chain, CVE-2026-55040, was previously disclosed by both parties last month. The exploitation status of CVE-2026-63520 is currently being discussed by Microsoft, determining whether immediate patching or continued monitoring is necessary. This vulnerability poses a significant threat as it allows for unauthenticated remote code execution against a vulnerable SharePoint server. The fix for this vulnerability has been released, and practitioners should prioritize patching to prevent potential attacks, as the exploitation status may change rapidly1.