Microsoft SharePoint is vulnerable to a remote code execution exploit, identified as CVE-2026-63520, which can be triggered by chaining it with another vulnerability, CVE-2026-55040. The discovery of this exploit is a result of a zero-day research project conducted by Rapid7 Labs, and both Rapid7 and Microsoft have disclosed the RCE vulnerability. The first vulnerability in the chain, CVE-2026-55040, was previously disclosed by both parties last month. The exploitation status of CVE-2026-63520 is currently being discussed by Microsoft, determining whether immediate patching or continued monitoring is necessary. This vulnerability poses a significant threat as it allows for unauthenticated remote code execution against a vulnerable SharePoint server. The fix for this vulnerability has been released, and practitioners should prioritize patching to prevent potential attacks, as the exploitation status may change rapidly1.
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
⚠️ Critical Alert
Why This Matters
CVE-2026-63520 is in active discussion involving Microsoft — exploitation status determines whether this is patch-now or monitor.
References
- Rapid7. (2026, August 11). CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED). Rapid7 Blog. https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed
Original Source
Rapid7 Blog
Read original →