CVE-2026-63520

Published Aug 11, 2026

Last updated 14 days ago

CVSS high 8.1
Microsoft Office SharePoint

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-63520 is a remote code execution (RCE) vulnerability affecting Microsoft SharePoint Server. This flaw stems from improper input validation, specifically an unsafe .NET type instantiation issue within SharePoint's Business Connectivity Services or its Federation Service. An attacker can exploit this vulnerability by crafting a malicious input or .NET gadget chain, enabling them to execute arbitrary code on the vulnerable server with the privileges of the SharePoint Site's service account. This vulnerability is frequently highlighted as the second part of a critical exploit chain when combined with CVE-2026-55040, an authentication bypass vulnerability. When chained together, these two vulnerabilities allow for unauthenticated remote code execution against a susceptible SharePoint server. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.

Description
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

16

  1. 🚨 SharePoint RCE Chain — Public PoCs Available CVE-2026-55040 → CVE-2026-63520 can be chained from authentication bypass to remote code execution. Public PoCs now exist for both flaws. https://t.co/CiNCJkZiQW #CVE #SharePoint #RCE #PoC #CyberSecurity #InfoSec https://t.

    @stem__shop

    27 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨Microsoft SharePointのRCEチェーンを攻撃者らが狙う:CVE-2026-55040、CVE-2026-63520 〜サイバーアラート8月27日〜 https://t.co/fHiBvWkERa

    @MachinaRecord

    27 Aug 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Microsoft SharePointの脆弱性を狙う活動-CVE-2026-55040はKEV掲載、CVE-2026-63520の技術詳細も公開 https://t.co/R5W8bJk0aU #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    @securityLab_jp

    27 Aug 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Attackers are chaining CVE-2026-55040 and CVE-2026-63520 to hit unpatched Microsoft SharePoint servers with remote code execution. Public PoC exploits are available, and active probing has been seen. #SharePoint #CISA #Defused https://t.co/Pgoiqf6bmX

    @TweetThreatNews

    26 Aug 2026

    136 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Defused warned: "We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots." Both flaws have public PoC exploits (Rapid7, Aug 11; VulnCheck, Aug 24); CISA ordered federal agencies to patch weeks ago. Shadowserver counts 8,700+ SharePoint

    @XavierRiveraX

    26 Aug 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2026-63520: SharePointのリモートコード実行(RCE)チェーンが実環境で調査され、概念実証(PoC)が公開されました CVE-2026-63520: SharePoint RCE Chain Probed in the Wild, PoC Public #DailyCyberSecurity (Aug 25) https://t.co/xQ5iKjTusR

    @foxbook

    26 Aug 2026

    156 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://t.co/w7WfofCvAh #CVE202655040 #CVE202663520 https://t.co/7Yysltrxm6

    @censysio

    25 Aug 2026

    3736 Impressions

    17 Retweets

    55 Likes

    27 Bookmarks

    0 Replies

    1 Quote

  8. Unauthenticated RCE Chain Found For Microsoft SharePoint CVE-2026-55040 and CVE-2026-63520 https://t.co/vk94Q747pB #decipher #deciphersec

    @DennisF

    25 Aug 2026

    179 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CRITICAL: A public exploit chain targeting Microsoft SharePoint is being actively probed in the wild. CVE-2026-55040 (authentication bypass) can be chained with CVE-2026-63520 (RCE) to achieve unauthenticated remote code execution on vulnerable SharePoint servers. @rapid7

    @ThreatWire_

    25 Aug 2026

    2186 Impressions

    0 Retweets

    5 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨🚨🚨 『when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers:』 Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://t.co/867lZwuPkF

    @autumn_good_35

    25 Aug 2026

    506 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  11. 🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain

    @DefusedCyber

    25 Aug 2026

    4701 Impressions

    9 Retweets

    42 Likes

    15 Bookmarks

    0 Replies

    1 Quote

  12. 🔒 #CyberSecurity CVE-2026-63520: Unauthenticated RCE in Microsoft SharePoint — Detection, Huntin… "Rapid7 has published analysis of CVE-2026-63520, an unauthenticated remote code execution…" 🔗 https://t.co/3aAnzxW3Hg #CyberSecurity #ThreatIntel #critical #zeroday

    @SecurityAr58409

    25 Aug 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 Patch Now | August 24, 2026 Bringing these CVEs to your attention! - Windows TFTP Server (CVE-2026-62893, CVSS 9.8 - SharePoint (CVE-2026-63520, CVSS 9.1) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3): https://t.co/1d3yDRvnoU | #CyberSafeUG #CERTUGCC https://t.co/pZmfJBv

    @CERT_UG

    24 Aug 2026

    226 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  14. The @VulnCheckAI Initial Access team has a blog out now on chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://t.co/qNQpuszjdr

    @catc0n

    24 Aug 2026

    3856 Impressions

    21 Retweets

    55 Likes

    35 Bookmarks

    0 Replies

    1 Quote

  15. Rapid7's AI-guided agent found a SharePoint chain reaching unauthenticated RCE: CVE-2026-55040 (JWT bypass, 9.1) plus CVE-2026-63520 (BCS .NET type instantiation, 8.1). Read full blog here: https://t.co/IbfwDIqL5L https://t.co/37H4Qem6dY

    @DarkInvaderIO

    20 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 August 19, 2026 Patch Advisories Today's advisories target these CVEs; - Microsoft Defender ShieldBreak (CVE-2026-69414) - SharePoint full RCE chain (CVE-2026-55040 and CVE-2026-63520 - Windows DNS Server (CVE-2026-62878, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG h

    @CERT_UG

    19 Aug 2026

    151 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/iOSW67KcaP

    @MSRResearchTX

    17 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/OnPFKt3Gi9

    @MSRResearchTX

    17 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/FoPyCnoack

    @MSRResearchTX

    17 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Technology Scout: Rapid7 flagged CVE-2026-63520 used with CVE-2026-55040 as a critical SharePoint patching priority affecting Subscription Edition, 2019, and 2016. Report: https://t.co/s0DpcYpC0d

    @MSRResearchTX

    17 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. ثغرتان في شيربوينت تتشابكان لتحقيق استغلال كامل عن بُعد دون مصادقة. المعرّف : CVE-2026-63520 درجة الخطورة : 8.1 (CVSS) - High السلسلة مع : CVE-2026-55040 → Unauthenticated RCE الحل : Appl

    @KasperskyDev

    16 Aug 2026

    296 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 【今月のMSアップデート解説】 8月のセキュリティ更新は今月も420件超と多め ・WinSock AFDの権限昇格(CVE-2026-68820)は悪用確認あり ・SharePoint等のRCEチェーン(CVE-2026-63520)も要注意 昨今、不正アクセスが増え

    @shunyat1031

    16 Aug 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🔒 #CyberSecurity CVE-2026-63520: Microsoft SharePoint Unauthenticated RCE Chained with CVE-2026-… "If you run on-premises Microsoft SharePoint, stop what you're doing and read this. Rapid7…" 🔗 https://t.co/LnteJVzCDY #CyberSecurity #ThreatIntel #critical #zeroday #c

    @SecurityAr58409

    11 Aug 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.