Stephen Fewer[verified]@stephenfewerGeneral
Rapid7 has released a technical analysis of the SharePoint RCE CVE‑2026‑63520, providing basic vulnerability type details but no PoC, exploit code, patch information, or evidence of active exploitation.
Stephen Fewer[verified]@stephenfewerDisclosure
Rapid7 publicly discloses an RCE vulnerability in SharePoint (CVE-2026-63520) with a link to a blog post; full technical details are to be released later.
Censys[verified]@censysioDisclosure
An advisory notes that CVE‑2026‑55040 and CVE‑2026‑63520 can be chained to bypass authentication and obtain RCE on Microsoft SharePoint Server, with no indication of active exploitation or available mitigation.
Nicolas Krassas[verified]@DinosnDisclosure
Rapid7’s blog post announces and analyses a Remote Code Execution vulnerability in Microsoft SharePoint (CVE‑2026‑63520).
dbugs[verified]@ptdbugsDisclosure
The article discloses a remote code execution flaw in Microsoft SharePoint's BDC subsystem, detailing how an authenticated attacker can use malicious .bdcm files to instantiate arbitrary .NET types and execute OS commands, though no PoC, exploit code, or patch is mentioned.
dbugs[verified]@ptdbugsExploit
A PoC/exploit for CVE‑2026‑63520 targeting Microsoft SharePoint Enterprise Server 2016 has been released on GitHub, demonstrating code execution via improper input validation, with no evidence of active exploitation or mitigation steps mentioned.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
The tweet announces that Rapid7 discovered CVE-2026-63520 on SharePoint Server, noting that linking it with CVE-2026-55040 can lead to a remote code execution chain, but provides no PoC, exploit, patch, or evidence of real‑world attacks.
ThreatWire[verified]@ThreatWire_Active Exploitation
Rapid7 reports that CVE‑2026‑55040 and CVE‑2026‑63520 can be chained into an active exploit against Microsoft SharePoint, urging users to apply patches immediately.