CVE-2026-63520
Published Aug 11, 2026
Last updated 14 days ago
AI description
CVE-2026-63520 is a remote code execution (RCE) vulnerability affecting Microsoft SharePoint Server. This flaw stems from improper input validation, specifically an unsafe .NET type instantiation issue within SharePoint's Business Connectivity Services or its Federation Service. An attacker can exploit this vulnerability by crafting a malicious input or .NET gadget chain, enabling them to execute arbitrary code on the vulnerable server with the privileges of the SharePoint Site's service account. This vulnerability is frequently highlighted as the second part of a critical exploit chain when combined with CVE-2026-55040, an authentication bypass vulnerability. When chained together, these two vulnerabilities allow for unauthenticated remote code execution against a susceptible SharePoint server. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.
- Description
- Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- sharepoint_server
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-20
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
16
🚨 SharePoint RCE Chain — Public PoCs Available CVE-2026-55040 → CVE-2026-63520 can be chained from authentication bypass to remote code execution. Public PoCs now exist for both flaws. https://t.co/CiNCJkZiQW #CVE #SharePoint #RCE #PoC #CyberSecurity #InfoSec https://t.
@stem__shop
27 Aug 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Microsoft SharePointのRCEチェーンを攻撃者らが狙う:CVE-2026-55040、CVE-2026-63520 〜サイバーアラート8月27日〜 https://t.co/fHiBvWkERa
@MachinaRecord
27 Aug 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft SharePointの脆弱性を狙う活動-CVE-2026-55040はKEV掲載、CVE-2026-63520の技術詳細も公開 https://t.co/R5W8bJk0aU #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
@securityLab_jp
27 Aug 2026
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining CVE-2026-55040 and CVE-2026-63520 to hit unpatched Microsoft SharePoint servers with remote code execution. Public PoC exploits are available, and active probing has been seen. #SharePoint #CISA #Defused https://t.co/Pgoiqf6bmX
@TweetThreatNews
26 Aug 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Defused warned: "We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots." Both flaws have public PoC exploits (Rapid7, Aug 11; VulnCheck, Aug 24); CISA ordered federal agencies to patch weeks ago. Shadowserver counts 8,700+ SharePoint
@XavierRiveraX
26 Aug 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-63520: SharePointのリモートコード実行(RCE)チェーンが実環境で調査され、概念実証(PoC)が公開されました CVE-2026-63520: SharePoint RCE Chain Probed in the Wild, PoC Public #DailyCyberSecurity (Aug 25) https://t.co/xQ5iKjTusR
@foxbook
26 Aug 2026
156 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://t.co/w7WfofCvAh #CVE202655040 #CVE202663520 https://t.co/7Yysltrxm6
@censysio
25 Aug 2026
3736 Impressions
17 Retweets
55 Likes
27 Bookmarks
0 Replies
1 Quote
Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520 https://t.co/vk94Q747pB #decipher #deciphersec
@DennisF
25 Aug 2026
179 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: A public exploit chain targeting Microsoft SharePoint is being actively probed in the wild. CVE-2026-55040 (authentication bypass) can be chained with CVE-2026-63520 (RCE) to achieve unauthenticated remote code execution on vulnerable SharePoint servers. @rapid7
@ThreatWire_
25 Aug 2026
2186 Impressions
0 Retweets
5 Likes
4 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨 『when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers:』 Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://t.co/867lZwuPkF
@autumn_good_35
25 Aug 2026
506 Impressions
1 Retweet
1 Like
1 Bookmark
1 Reply
0 Quotes
🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain
@DefusedCyber
25 Aug 2026
4701 Impressions
9 Retweets
42 Likes
15 Bookmarks
0 Replies
1 Quote
🔒 #CyberSecurity CVE-2026-63520: Unauthenticated RCE in Microsoft SharePoint — Detection, Huntin… "Rapid7 has published analysis of CVE-2026-63520, an unauthenticated remote code execution…" 🔗 https://t.co/3aAnzxW3Hg #CyberSecurity #ThreatIntel #critical #zeroday
@SecurityAr58409
25 Aug 2026
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Patch Now | August 24, 2026 Bringing these CVEs to your attention! - Windows TFTP Server (CVE-2026-62893, CVSS 9.8 - SharePoint (CVE-2026-63520, CVSS 9.1) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3): https://t.co/1d3yDRvnoU | #CyberSafeUG #CERTUGCC https://t.co/pZmfJBv
@CERT_UG
24 Aug 2026
226 Impressions
2 Retweets
4 Likes
0 Bookmarks
0 Replies
1 Quote
The @VulnCheckAI Initial Access team has a blog out now on chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://t.co/qNQpuszjdr
@catc0n
24 Aug 2026
3856 Impressions
21 Retweets
55 Likes
35 Bookmarks
0 Replies
1 Quote
Rapid7's AI-guided agent found a SharePoint chain reaching unauthenticated RCE: CVE-2026-55040 (JWT bypass, 9.1) plus CVE-2026-63520 (BCS .NET type instantiation, 8.1). Read full blog here: https://t.co/IbfwDIqL5L https://t.co/37H4Qem6dY
@DarkInvaderIO
20 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h
@CERT_UG
19 Aug 2026
151 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/iOSW67KcaP
@MSRResearchTX
17 Aug 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/OnPFKt3Gi9
@MSRResearchTX
17 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/FoPyCnoack
@MSRResearchTX
17 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/s0DpcYpC0d
@MSRResearchTX
17 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ثغرتان في شيربوينت تتشابكان لتحقيق استغلال كامل عن بُعد دون مصادقة. المعرّف : CVE-2026-63520 درجة الخطورة : 8.1 (CVSS) - High السلسلة مع : CVE-2026-55040 → Unauthenticated RCE الحل : Appl
@KasperskyDev
16 Aug 2026
296 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【今月のMSアップデート解説】 8月のセキュリティ更新は今月も420件超と多め ・WinSock AFDの権限昇格(CVE-2026-68820)は悪用確認あり ・SharePoint等のRCEチェーン(CVE-2026-63520)も要注意 昨今、不正アクセスが増え
@shunyat1031
16 Aug 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-63520: Microsoft SharePoint Unauthenticated RCE Chained with CVE-2026-… "If you run on-premises Microsoft SharePoint, stop what you're doing and read this. Rapid7…" 🔗 https://t.co/LnteJVzCDY #CyberSecurity #ThreatIntel #critical #zeroday #c
@SecurityAr58409
11 Aug 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
"matchCriteriaId": "D918B8DF-51D1-46F3-8B3F-E4370083BEF6",
"versionEndExcluding": "16.0.19725.20522",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F815EF1D-7B60-47BE-9AC2-2548F99F10E4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "6122D014-5BF1-4AF4-8B4D-80205ED7785E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]