47
42
30
30
55
55
47
60
30
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Rapid7 and Microsoft disclose CVE-2026-63520, a SharePoint RCE that chains with CVE-2026-55040 for unauthenticated RCE; patches released.
Rapid7 Labs' zero-day research project on Microsoft SharePoint uncovered two vulnerabilities that, when chained, achieve unauthenticated remote code execution. The second flaw in the chain, CVE-2026-63520, affects all supported versions of Microsoft SharePoint and has been disclosed and fixed. The first chain component, CVE-2026-55040, was disclosed by Rapid7 and Microsoft the previous month.
78
30
55
42
42
30
60
42
47
55
42
47
55
35
42
42
55
60
60
60
30
30
30
30
42
47
47
35
55
42
55