AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2026-63520

Vendor unknownProduct mapping pending

Metadata pending authoritative retrieval.

VTP deterministic threat22.0of 100 · CVSS excluded

VTP analyst assessment

No AI candidate assessment for this subject

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationNO ALERT
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factUNKNOWN

Assessment

The latest persisted AI review did not propose this CVE for analyst escalation. Deterministic monitoring remains authoritative for the factual states below.

Why it matters

Unknown from persisted AI analysis.

Evidence

No AI candidate evidence set is persisted for this CVE.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

Independent primary confirmation of active exploitation would materially change this assessment.

AI analysis history (0)
    Technical severityUNKNOWNCVSS unknown · technical context
    Public exploitationUNKNOWNGlobal public evidence
    Exploit maturityTECHNICAL DETAILSReliability not implied
    EPSSPrediction unavailable
    Evidence confidence86%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryNo first-party sensor telemetry configured.
    Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      No first-party sensor telemetry is configured; first-party observation is unknown.

    02

    Material change ledger

    What changed

    RESEARCH PUBLICATIONNew technical research
    ZERO DAYZero Day
    03

    Claim provenance

    Evidence and source independence

    1publications detected
    1underlying evidence chains

    1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
    86%claim confidence
    INDEPENDENTreport:964bc566b710bd8f03f63a93b4800cd8b8283d343a7958439cbdb0edce9853e9ACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 13:0011 Aug
      RESEARCH PUBLICATION

      New technical research

      Rapid7 Research published evidence linked to CVE-2026-63520.

    2. 13:0011 Aug
      ZERO DAY

      Zero Day

      Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

    05

    Original publications

    Source record

    CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

    Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to disclosure. ⠀ CVE-2026-63520 affects all supported versions of Microsoft SharePoint, and certain versions of Microsoft Project Server and Microsoft Office Web Apps Server. For the purpose of our research, we focused solely on SharePoint. An attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. The vulnerability is due to an unsafe .NET type instantiation issue within the Business Connectivity Services . CVE-2026-63520 has a CVSSv3.1 score of 8.1 (High) , and a Common Weakness Enumeration (CWE) of CWE-20: Improper Input Validation . While the severity of the RCE is described as high, chained together with CVE-2026-55040 it becomes part of a critical unauthenticated RCE exploit chain against SharePoint. The exploit chain was developed as an entry for this year's Pwn2Own Berlin hacking competition; while our entry was unsuccessful on the day of the competition, this research highlights Rapid7 Labs' continued effort to raise the bar in Vulnerability Intelligence and our commitment to the preemptive protection of our customers through original vulnerability research. Our research methodology focused on understanding how publicly available AI models can assist in the discovery of significant vulnerabilities against proprietary enterprise targets. Our results established that the rate of model advancement is significantly accelerating vulnerability research, model guidance from subject matter experts is a force multiplier, and complex proprietary targets are easily handled through agentic workflows. Rapid7 is hosting a webinar on Thursday August 13, 2026 to discuss the research and findings for CVE-2026-55040 and CVE-2026-63520. Please join Douglas McKee and Stephen Fewer to learn more about this body of work. Workflow For this research project we wanted to understand the capabilities and limits of publicly available LLMs circa January through to March of this year. We wanted to answer the question if an AI workflow could find and develop an unauthenticated RCE exploit against a hard target such as SharePoint. This research project concluded with the successful discovery and development of such a chain. To that end, the publicly available models at the beginning of this year were indeed capable. This is notable as the rate of model improvement from Q1 of 2026 through to today has been significant. Our team's later testing of the most recent frontier models confirms the significant increase in capabilities from that of the beginning of this year. Our primary conclusion from the SharePoint research project in Q1 is that an agent guided by a subject matter expert (SME) was crucial to keep moving the model and its work towards the end goal. Given our current experience of frontier model capabilities, the need for an SME to verify and guide a model is lessened, but the compounding impact an SME can bring remains. Our first sprint in January did not result in any significant findings, rather, this sprint helped us establish the workflow and tooling that proved most useful, scope out the extremely large attack surface, and integrate prior work into our process. We augmented the agentic work with manual source code review and reverse engineering to provide additional context and steering to the model. Our early results quickly indicated how a fully aut

    CVE-2026-55040CVE-2026-63520
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score22.0vtp-threat-v1-public
    Public exploitation0 / 30
    EPSS prediction0 / 20
    Exploit availability2.5 / 15
    Source independence7.5 / 15
    Intelligence recency10 / 10
    Threat acceleration2 / 10
    CVSS technical severityExcluded
    CVSS
    Unknown · UNKNOWN
    Vector
    Unknown
    CWE
    Unknown
    CPE records
    0
    Deterministic history records
    1
    07

    Raw observations

    First-party sensor records

    No first-party sensor telemetry configured.