42
42
60
42
42
42
47
42
42
42
47
47
42
42
42
47
42
42
42
47
42
47
60
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Rapid7 and Microsoft disclose CVE-2026-63520, a SharePoint RCE that chains with CVE-2026-55040 for unauthenticated RCE; patches released.
Rapid7 Labs' zero-day research project on Microsoft SharePoint uncovered two vulnerabilities that, when chained, achieve unauthenticated remote code execution. The second flaw in the chain, CVE-2026-63520, affects all supported versions of Microsoft SharePoint and has been disclosed and fixed. The first chain component, CVE-2026-55040, was disclosed by Rapid7 and Microsoft the previous month.
78
42
42
42
47
42
47
42
42
42
47
47
42
47
42
47
57