CVE-2026-63520Disclosure(microsoft / sharepoint_server)

CRITICALCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 19 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 73 mentions across 15 observed days

What's happening

  • Active exploitation reported across 19 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 25 signals
  • Patch or workaround mentioned in 33 signals
  • Technical details provided in 64 signals
  • Disclosure: 19 classified signals
  • Peaked 14d ago at 12 mentions (2026-08-11); latest day: 1
  • 73 total mentions across 15 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline73 mentions / 15d
036912Mentions · 2026-08-11: 12Mentions · 2026-08-12: 10Mentions · 2026-08-13: 6Mentions · 2026-08-14: 1Mentions · 2026-08-16: 2Mentions · 2026-08-19: 4Mentions · 2026-08-20: 2Mentions · 2026-08-24: 4Mentions · 2026-08-25: 10Mentions · 2026-08-26: 5Mentions · 2026-08-27: 10Mentions · 2026-08-30: 2Mentions · 2026-08-31: 1Mentions · 2026-09-03: 3Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-08-11: 2PoC Mentioned / Linked · 2026-08-12: 2PoC Mentioned / Linked · 2026-08-13: 2PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-25: 7PoC Mentioned / Linked · 2026-08-26: 5PoC Mentioned / Linked · 2026-08-27: 2PoC Mentioned / Linked · 2026-08-30: 1PoC Mentioned / Linked · 2026-09-14: 1Exploit Tool / Code · 2026-08-13: 2Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-08-26: 3Exploit Tool / Code · 2026-08-27: 1Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-08-12: 3Active Exploitation · 2026-08-13: 2Active Exploitation · 2026-08-16: 1Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-25: 2Active Exploitation · 2026-08-26: 4Active Exploitation · 2026-08-27: 2Active Exploitation · 2026-08-30: 1Active Exploitation · 2026-08-31: 1Active Exploitation · 2026-09-14: 1Patch / Workaround · 2026-08-11: 8Patch / Workaround · 2026-08-12: 6Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 4Patch / Workaround · 2026-08-26: 2Patch / Workaround · 2026-08-27: 3Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-03: 1Technical Details · 2026-08-11: 9Technical Details · 2026-08-12: 9Technical Details · 2026-08-13: 6Technical Details · 2026-08-16: 2Technical Details · 2026-08-19: 4Technical Details · 2026-08-20: 2Technical Details · 2026-08-24: 4Technical Details · 2026-08-25: 9Technical Details · 2026-08-26: 5Technical Details · 2026-08-27: 7Technical Details · 2026-08-30: 2Technical Details · 2026-08-31: 1Technical Details · 2026-09-03: 3Technical Details · 2026-09-14: 108-1108-1208-1308-1408-1608-1908-2008-2408-2508-2608-2708-3008-3109-0309-14
Signal classification6 categories
Disclosure
1926.0%
Patch
1824.7%
Active Exploitation
1723.3%
General
811.0%
PoC
68.2%
Exploit
56.8%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-1112
Active Exploitation1Disclosure3Patch7PoC1
2026-08-1210
Active Exploitation3Disclosure2General1Patch4
2026-08-136
Active Exploitation1Disclosure4Exploit1
2026-08-141
Patch1
2026-08-162
Active Exploitation1Patch1
2026-08-194
Active Exploitation1Patch1PoC2
2026-08-202
Disclosure1Patch1
2026-08-244
Disclosure1General2Patch1
2026-08-2510
Active Exploitation2Disclosure3Exploit2General2PoC1
2026-08-265
Active Exploitation3Exploit1PoC1
2026-08-2710
Active Exploitation2Disclosure2Exploit1General3Patch1PoC1
2026-08-302
Active Exploitation1Disclosure1
2026-08-311
Active Exploitation1
2026-09-033
Disclosure2Patch1
2026-09-141
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    🛑 No SharePoint credentials needed to impersonate an admin and run code. Researchers chained two flaws, CVE-2026-55040 and CVE-2026-63520, to go from unauthenticated user impersonation to code execution on the server. Read details here: https://thehackernews.com/2026/08/researchers-disclose-ai-assisted.html

    Post summary

    The text announces that researchers have disclosed two chained CVEs in SharePoint enabling unauthenticated impersonation and server‑side code execution, without referencing PoCs, exploits, or patches.

    23311104034.4K
    2.4M followersView on X
  • Stephen Fewer@stephenfewer
    General

    We have published a technical analysis for CVE-2026-63520, the Microsoft SharePoint RCE we disclosed earlier this month: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/

    Post summary

    Rapid7 has released a technical analysis of the SharePoint RCE CVE‑2026‑63520, providing basic vulnerability type details but no PoC, exploit code, patch information, or evidence of active exploitation.

    025091328.4K
    10.0K followersView on X
  • Caitlin Condon@catc0n
    General

    The @VulnCheckAI Initial Access team has a blog out now on chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

    Post summary

    The tweet announces a blog discussing how chaining CVE‑2026‑55040 and CVE‑2026‑63520 leads to an authentication bypass and remote code execution in SharePoint, offering technical details but no PoC, exploit code, or patch information.

    023157374.9K
    3.6K followersView on X
  • Stephen Fewer@stephenfewer
    Disclosure

    Today we are also disclosing the RCE vulnerability from our SharePoint exploit chain, CVE-2026-63520. Disclosure details are here and full technical details to be published at a later date: https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed/

    Post summary

    Rapid7 publicly discloses an RCE vulnerability in SharePoint (CVE-2026-63520) with a link to a blog post; full technical details are to be released later.

    1212722014.6K
    10.0K followersView on X
  • Censys@censysio
    Disclosure

    🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://bit.ly/4zJA1SK #CVE202655040 #CVE202663520 https://t.co/7Yysltrxm6

    Post summary

    An advisory notes that CVE‑2026‑55040 and CVE‑2026‑63520 can be chained to bypass authentication and obtain RCE on Microsoft SharePoint Server, with no indication of active exploitation or available mitigation.

    021160274.5K
    12.6K followersView on X
  • Defused@DefusedCyber
    General

    🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain writeup published yesterday by @VulnCheckAI Full details on Defused Radar 👉 http://console.defusedcyber.com/radar

    Post summary

    The post reports that a SharePoint RCE chain involving CVE-2026-55040 and CVE-2026-63520 has been probed in honeypots and a writeup detailing the chain is available, but no successful exploitation or further technical or mitigation information is disclosed.

    09147155.6K
    7.7K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520

    Post summary

    Rapid7’s blog post announces and analyses a Remote Code Execution vulnerability in Microsoft SharePoint (CVE‑2026‑63520).

    07033115.3K
    161.5K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE-2026-63520: RCE in Microsoft SharePoint via unsafe .NET type initialization The vulnerability CVE-2026-63520 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-63520) affects Microsoft SharePoint and allows an authenticated attacker to execute arbitrary code on the server with the privileges of the SharePoint service account. The issue is related to the Business Data Connectivity (BDC) subsystem, which lacks secure validation when resolving and instantiating .NET types from user-controlled BDC models. Specifically, the method "Type.GetType()" is called based on attacker-controlled data without validation, enabling the creation of arbitrary objects. Exploitation is possible by uploading a malicious ".bdcm" file and building a gadget chain (for example, through "ObjectDataProvider") followed by a call to "Process.Start()" to execute commands at the OS level. Combined with CVE-2026-55040 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-55040) (authentication bypass), the attack can be extended, significantly increasing its severity and simplifying remote exploitation without credentials. Article: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/ #dbugs_attacks

    Post summary

    The article discloses a remote code execution flaw in Microsoft SharePoint's BDC subsystem, detailing how an authenticated attacker can use malicious .bdcm files to instantiate arbitrary .NET types and execute OS commands, though no PoC, exploit code, or patch is mentioned.

    0401791.3K
    3.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-63520 Vendor: Microsoft Product: Microsoft SharePoint Enterprise Server 2016 Description: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Link: https://github.com/hypnguyen1209/cve-2026-63520 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE‑2026‑63520 targeting Microsoft SharePoint Enterprise Server 2016 has been released on GitHub, demonstrating code execution via improper input validation, with no evidence of active exploitation or mitigation steps mentioned.

    0701371.0K
    3.6K followersView on X
  • Rapid7@rapid7
    PoC

    Today, both Rapid7 and #Microsoft are disclosing the 2nd vuln in this chain – CVE-2026-63520 – alongside all-new analysis & PoC for CVE-2026-55040, which was disclosed last month. 👉 Aug. disclosure: https://r-7.co/4wVaO5T 👉 Jul. analysis & PoC: https://r-7.co/4xEF4C5

    Post summary

    Rapid7 and Microsoft disclose CVE-2026-63520 and provide new analysis and PoC for CVE-2026-55040, with August and July links to the details.

    12012103.2K
    125.9K followersView on X
  • VulnCheck@VulnCheckAI
    Exploit

    VulnCheck developed the first weaponized exploit chaining two recently patched Microsoft SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to bypass authentication and achieve remote code execution. Read the full analysis: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

    Post summary

    VulnCheck reports a weaponized exploit that chains two patched SharePoint CVEs to bypass authentication and achieve remote code execution, highlighting the vulnerability’s practical exploitability.

    0501131.3K
    894 followersView on X
  • DirectoryRanger@DirectoryRanger
    Disclosure

    Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/

    Post summary

    The post announces a new Remote Code Execution flaw in Microsoft SharePoint (CVE‑2026‑63520) but does not offer PoC details, exploit code, or mitigation information.

    040661.9K
    37.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    اذا تستخدمون SharePoint Server راجعوا تحديثات شهر Aug 🚨 باحثو Rapid7 كشفوا ثغرة CVE-2026-63520. عند ربطها بثغرة الشهر الماضي CVE-2026-55040 تصير سلسلة RCE المطمئن ان عدد السيرفرات المكشوفه على الانترنت في السعودية قليل جداً 🤩 التفاصيل: 🧵👇 https://t.co/RXDEj7VdWZ

    Post summary

    The tweet announces that Rapid7 discovered CVE-2026-63520 on SharePoint Server, noting that linking it with CVE-2026-55040 can lead to a remote code execution chain, but provides no PoC, exploit, patch, or evidence of real‑world attacks.

    131732.4K
    50.2K followersView on X
  • ThreatWire@ThreatWire_
    Active Exploitation

    🚨 CRITICAL: A public exploit chain targeting Microsoft SharePoint is being actively probed in the wild. CVE-2026-55040 (authentication bypass) can be chained with CVE-2026-63520 (RCE) to achieve unauthenticated remote code execution on vulnerable SharePoint servers. @rapid7 has now published technical details and exploit research. 🔴 Patch both vulnerabilities immediately. 🔗 https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/ #Microsoft #SharePoint #CVE #RCE #Exploit #CyberSecurity #Infosec

    Post summary

    Rapid7 reports that CVE‑2026‑55040 and CVE‑2026‑63520 can be chained into an active exploit against Microsoft SharePoint, urging users to apply patches immediately.

    000752.9K
    1.6K followersView on X
  • National CERT/CC@CERT_UG
    Patch

    🚨 Patch Now | August 24, 2026 Bringing these CVEs to your attention! - Windows TFTP Server (CVE-2026-62893, CVSS 9.8 - SharePoint (CVE-2026-63520, CVSS 9.1) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3): http://cert.ug | #CyberSafeUG #CERTUGCC https://t.co/pZmfJBv2yz

    Post summary

    The post identifies three critical CVEs with high CVSS scores and urges immediate patching, without providing exploit details or PoC code.

    03160352
    1.5K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔓 Attackers are probing a Microsoft SharePoint RCE chain combining CVE-2026-55040 and CVE-2026-63520. The flaws can enable authentication bypass and remote code execution on exposed on-premises servers. Patch immediately. #CyberSecurity #Microsoft Read more: https://thecyberedition.com/microsoft-sharepoint-rce-chain-exploited-as-attackers-probe-critical-cve-2026-55040-flaw/

    Post summary

    The post alerts that attackers are probing a SharePoint RCE chain involving CVE‑2026‑55040 and CVE‑2026‑63520, highlights authentication bypass and RCE as technical details, and urges immediate patching.

    01033320
    768 followersView on X
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Disclosure

    🚨 $ICP — ANOTHER CRACK IN THE OLD INTERNET. HOW MANY MORE WARNINGS DO PEOPLE NEED? @Office SharePoint Server has another serious remote-code-execution vulnerability. CVE-2026-63520 allows an unauthorized attacker to execute code across a network and carries a CVSS score of 8.1. Rapid7 says it affects supported SharePoint versions and stems from unsafe .NET type instantiation within Business Connectivity Services. (Rapid7) Now combine it with CVE-2026-55040. That earlier SharePoint vulnerability allows an unauthenticated attacker to bypass authentication. Microsoft rates CVE-2026-55040 CRITICAL at 9.1. CHAIN THEM TOGETHER: AUTHENTICATION BYPASS ➜ REMOTE CODE EXECUTION. No credentials. Remote attack. Enterprise infrastructure compromised. And people still think I am being dramatic when I say the architecture of the internet itself has to change. Cloud breaches. Supply-chain attacks. Ransomware. Compromised applications. Stolen API keys. Fake browser extensions. Authentication failures. Remote code execution. I KEEP POSTING THESE FOR A REASON. I do not see isolated vulnerabilities. I see the direction of travel. AI agents, autonomous systems, digital identity, machine-to-machine commerce and billions more connected services are about to massively increase the amount of software we are expected to TRUST. That model cannot scale forever. The future needs VERIFIABLE COMPUTATION. The future needs software whose integrity can be cryptographically proven. The future needs infrastructure that does not continuously ask humanity to trust another server, administrator, cloud account or intermediary. From everything I have researched, I see ONE safe harbour for the digital world that lies ahead. $ICP. Not another token. AN ENTIRE ALTERNATIVE INTERNET COMPUTING STACK. The old internet will continue patching yesterday’s architecture. ICP is building for tomorrow’s. You will all eventually understand why that distinction matters. 🐘 $ICP IS THE ELEPHANT IN THE ROOM. #ICP #InternetComputer #DFINITY #Microsoft #SharePoint #CyberSecurity #InfoSec #ZeroTrust #CloudSecurity #AI #Blockchain #Web3 #FutureOfInternet ☕ Support my $ICP content: 1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362

    Post summary

    The post highlights two severe SharePoint vulnerabilities—CVE-2026-63520 (remote code execution) and CVE-2026-55040 (authentication bypass)—and urges a shift in internet architecture rather than providing proof of exploitation or patch details.

    01150295
    1.7K followersView on X
  • !Manan@0xManan
    General

    CVE-2026-63520 alone needs auth. CVE-2026-55040 alone is "just" a JWT bypass. together they're unauth RCE. severity lives in the glue, not either ticket. https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

    Post summary

    The post describes how two separate CVEs can be combined to achieve unauthenticated remote code execution, but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    00040175
    2.1K followersView on X
  • Autumn Good@autumn_good_35
    Exploit

    🚨🚨🚨 『when used together, allow a remote unauthenticated adversary to bypass authentication and execute code on vulnerable target SharePoint servers:』 Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce

    Post summary

    The post highlights that CVE-2026-55040 and CVE-2026-63520 can be chained to achieve remote unauthenticated authentication bypass and code execution on SharePoint, with a blog link likely containing a PoC.

    11011555
    7.0K followersView on X
  • SonicWall@SonicWall
    Disclosure

    Microsoft patched 422 vulnerabilities this August. 63 are critical. One is a SharePoint RCE (CVE-2026-63520) that bypasses authentication. Our Capture Labs team built detection coverage for 24 of them. Full list ➡️ https://bit.ly/4zGOwGN #SonicWallAlerts

    Post summary

    Microsoft released a patch for CVE-2026-63520, a SharePoint RCE that bypasses authentication, and Capture Labs has added detection coverage for this and other vulnerabilities.

    10011511
    29.2K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more