Vulnerability threat dossier

CVE-2026-63520

microsoftsharepoint server

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

VTP deterministic threat36.6of 100 · CVSS excluded

VTP analyst assessment

Microsoft SharePoint input-validation RCE

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence91%
Public exploitation · VTP factCONFIRMED

Assessment

Improper input validation in SharePoint permits unauthenticated network code execution with CVSS 3.1 score 8.1 and high attack complexity. Supplied independent assertions report active exploitation and zero-day status; unlike the related SharePoint entry, this CVE is not listed as KEV in the bundle, and VTP observation is unknown.

Why it matters

  • Successful exploitation can compromise confidentiality, integrity, and availability across SharePoint 2016, 2019, and Subscription Edition.
  • The active-exploitation and zero-day assertions provide stronger context than EPSS, which remains predictive only.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The exploit conditions, chain dependencies, and technical details are not included.

The bundle does not establish public exploit reliability, campaign scope, or VTP observation.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Affected SharePoint editions, build levels, and network exposure.

AI baseline history (3)
  1. BASELINE ASSESSED
    Microsoft SharePoint input-validation RCEgpt-5.6-sol · high
  2. BASELINE ASSESSED
    SharePoint improper-input-validation remote code executiongpt-5.6-sol · high
  3. BASELINE ASSESSED
    SharePoint unauthenticated RCE with technical detailsgpt-5.6-sol · high

Previous AI priority: HIGH → current: HIGH. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityHIGHCVSS 8.1 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0386th percentile · prediction
Evidence confidence86%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    EPSS is 0.03; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

RESEARCH PUBLICATIONNew technical research
CERT ADVISORYNew CERT advisory
RESEARCH PUBLICATIONNew technical research
RESEARCH PUBLICATIONNew technical research
ZERO DAYZero Day
RESEARCH PUBLICATIONNew technical research
ACTIVE EXPLOITATIONActive Exploitation
03

Claim provenance

Evidence and source independence

11publications detected
11underlying evidence chains

3 primary sources · 0 dependent secondary reports · 6 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
86%claim confidence
INDEPENDENTreport:964bc566b710bd8f03f63a93b4800cd8b8283d343a7958439cbdb0edce9853e9ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
82%claim confidence
INDEPENDENTreport:964bc566b710bd8f03f63a93b4800cd8b8283d343a7958439cbdb0edce9853e9ACTIVE
Evidence
04

Event history

Threat timeline

  1. 16:1824 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-63520.

  2. 00:0012 Aug
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-63520.

  3. 22:2111 Aug
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2026-63520.

  4. 21:1011 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-63520.

  5. 13:0011 Aug
    ZERO DAY

    Zero Day

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  6. 13:0011 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-63520.

  7. 13:0011 Aug
    ACTIVE EXPLOITATION

    Active Exploitation

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

CVE-2026-55040CVE-2026-63520
Separate evidence group
Original

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]

CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-63520
Separate evidence group
Original

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

CVE-2019-1257CVE-2026-55040CVE-2026-63520
Separate evidence group
Original

SharePoint Vulnerability Exploited Shortly After PoC Release

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek .

CVE-2026-45659CVE-2026-50522CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-63520
Separate evidence group
Original

Multiples vulnérabilités dans les produits Microsoft (12 août 2026)

De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

CVE-2026-40375CVE-2026-47285CVE-2026-54123CVE-2026-54981CVE-2026-57105CVE-2026-58612CVE-2026-58639CVE-2026-58650CVE-2026-59113CVE-2026-59119CVE-2026-62827CVE-2026-62829CVE-2026-62837CVE-2026-62839CVE-2026-62871CVE-2026-62886CVE-2026-62897CVE-2026-62898CVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62902CVE-2026-62909CVE-2026-62910CVE-2026-62911CVE-2026-62912CVE-2026-62913CVE-2026-62914CVE-2026-62915CVE-2026-62917CVE-2026-63512CVE-2026-63514CVE-2026-63516CVE-2026-63520CVE-2026-64897CVE-2026-64900CVE-2026-64901CVE-2026-64902CVE-2026-64916CVE-2026-64921CVE-2026-64922CVE-2026-65658CVE-2026-65660CVE-2026-65663CVE-2026-65665CVE-2026-65673CVE-2026-65675CVE-2026-65680CVE-2026-65767CVE-2026-65768CVE-2026-65769CVE-2026-65811CVE-2026-65813CVE-2026-65815CVE-2026-66301CVE-2026-66805CVE-2026-66808CVE-2026-68821CVE-2026-69278CVE-2026-69306CVE-2026-69320CVE-2026-70306CVE-2026-70321CVE-2026-70324CVE-2026-70326CVE-2026-70335CVE-2026-70336CVE-2026-70337CVE-2026-70338CVE-2026-70354CVE-2026-70355
Separate evidence group
Original

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."

CVE-2026-49163CVE-2026-50481CVE-2026-50515CVE-2026-50516CVE-2026-56161CVE-2026-56162CVE-2026-58650CVE-2026-59115CVE-2026-59118CVE-2026-59124CVE-2026-59132CVE-2026-59133CVE-2026-61348CVE-2026-61358CVE-2026-61925CVE-2026-61929CVE-2026-61930CVE-2026-62688CVE-2026-62696CVE-2026-62698CVE-2026-62712CVE-2026-62713CVE-2026-62721CVE-2026-62735CVE-2026-62737CVE-2026-62741CVE-2026-62766CVE-2026-62783CVE-2026-62788CVE-2026-62815CVE-2026-62816CVE-2026-62817CVE-2026-62818CVE-2026-62819CVE-2026-62820CVE-2026-62822CVE-2026-62823CVE-2026-62824CVE-2026-62827CVE-2026-62830CVE-2026-62832CVE-2026-62836CVE-2026-62869CVE-2026-62873CVE-2026-62878CVE-2026-62888CVE-2026-62889CVE-2026-62890CVE-2026-62893CVE-2026-62896CVE-2026-62911CVE-2026-62918CVE-2026-63508CVE-2026-63513CVE-2026-63515CVE-2026-63518CVE-2026-63519CVE-2026-63520CVE-2026-63522CVE-2026-63525CVE-2026-63526CVE-2026-63532CVE-2026-64898CVE-2026-64903CVE-2026-64907CVE-2026-64909CVE-2026-64910CVE-2026-64911CVE-2026-64921CVE-2026-65657CVE-2026-65664CVE-2026-65665CVE-2026-65667CVE-2026-65668CVE-2026-65775CVE-2026-65788CVE-2026-65789CVE-2026-65791CVE-2026-66799CVE-2026-66802CVE-2026-66804CVE-2026-66807CVE-2026-68794CVE-2026-68804CVE-2026-68816CVE-2026-68820CVE-2026-68823CVE-2026-69278CVE-2026-70130CVE-2026-70307CVE-2026-70332CVE-2026-70335CVE-2026-70355CVE-2026-71331
Separate evidence group
Original

Patch Tuesday - August 2026

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft; this vulnerability is the second in a pair of exploits which, when chained together, comprise a critical unauthenticated remote code execution vulnerability in a vulnerable SharePoint server. Patches are available for SharePoint Server Subscription Edition, 2019, and 2016. Alongside today’s coordinated disclosure of CVE-2026-63520 , Rapid7 has now published a detailed technical analysis and proof-of-concept for CVE-2026-55040 , the first vulnerability in the chain. AFD for Winsock: zero-day EoP Rapid7 has previously discussed the Windows Ancillary Function Driver for WinSock, and today it returns to center stage with another exploited-in-the-wild elevation-of-privilege vulnerability. Successful exploitation requires winning a race condition, which increases the difficulty of producing a stable exploit. This also helps keep the CVSS v3 base score down to 7.0, along with a Microsoft proprietary severity ranking of merely important, rather than critical. However, with no user interaction required, and a prize of SYSTEM-level access, CVE-2026-68820 is just what the doctor ordered, if the doctor is based in Pyongyang and wants to steal your cryptocurrency. Microsoft credits CVE-2026-68820 to researchers at Check Point (misspelled “Checkpoint” on the advisory). CVE-2026-68820 isn’t yet listed on CISA KEV, but it will be soon. What’s the opposite of coordinated disclosure? This month’s entry in the ongoing saga of Microsoft vs. a pseudonymous security researcher with a clear dislike of Microsoft comes in the form of CVE-2026-62832 , an elevation of privilege vulnerability in the Windows User Profile Service. Exploitation leads to administrator rights on the local asset, and is achieved via a specially crafted application, which is Microsoft corporate argot for exploit code. Between the public disclosure and the FAQ, which describes an authenticated attacker who has credentials for another account and loads another user’s registry hive, the advisory is a solid match for Nightmare Eclipse’s description of LegacyHive, which Rapid7 discussed last month . Patch Tuesday watchers will have been wondering whether Nightmare Eclipse would continue the pattern of the past few months by dropping yet another zero-day vuln late on Patch Tuesday to maximize friction and inconvenience for Microsoft. Wonder no more, because the new entry on this growing list of headaches is ShieldBreak. Nightmare Eclipse describes ShieldBreak as a full patch bypass for RoguePlanet, a previous entry in the series which Microsoft patched as CVE-2026-50656 during July, a month after its public disclosure. Both vulnerabilities are therefore elevation-of-privilege to SYSTEM vulnerabilities in Defender. Container isolation filesystem driver: isolation failure, tampering CVE-2026-72971 describes a tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys), where abuse of a flaw in the vulnerable driver presumably allows an una

CVE-2026-50656CVE-2026-55040CVE-2026-62832CVE-2026-63520CVE-2026-68820CVE-2026-72971
Separate evidence group
Original

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

CVE-2026-55040CVE-2026-59124CVE-2026-62815CVE-2026-62878CVE-2026-62893CVE-2026-63520CVE-2026-68820
Separate evidence group
Original

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]

CVE-2026-18577CVE-2026-40375CVE-2026-42976CVE-2026-47285CVE-2026-47299CVE-2026-49163CVE-2026-49179CVE-2026-50472CVE-2026-50481CVE-2026-50515CVE-2026-50516CVE-2026-54113CVE-2026-54123CVE-2026-54981CVE-2026-54984CVE-2026-56161CVE-2026-56162CVE-2026-56174CVE-2026-56179CVE-2026-57104CVE-2026-57105CVE-2026-58612CVE-2026-58639CVE-2026-58641CVE-2026-58650CVE-2026-58651CVE-2026-59113CVE-2026-59115CVE-2026-59118CVE-2026-59119CVE-2026-59122CVE-2026-59124CVE-2026-59125CVE-2026-59126CVE-2026-59127CVE-2026-59128CVE-2026-59130CVE-2026-59131CVE-2026-59132CVE-2026-59133CVE-2026-59134CVE-2026-59135CVE-2026-59136CVE-2026-59137CVE-2026-59138CVE-2026-61345CVE-2026-61346CVE-2026-61347CVE-2026-61348CVE-2026-61349CVE-2026-61350CVE-2026-61352CVE-2026-61353CVE-2026-61355CVE-2026-61356CVE-2026-61357CVE-2026-61358CVE-2026-61359CVE-2026-61360CVE-2026-61361CVE-2026-61363CVE-2026-61364CVE-2026-61365CVE-2026-61366CVE-2026-61367CVE-2026-61368CVE-2026-61918CVE-2026-61920CVE-2026-61921CVE-2026-61923CVE-2026-61924CVE-2026-61925CVE-2026-61926CVE-2026-61927CVE-2026-61928CVE-2026-61929CVE-2026-61930CVE-2026-61932CVE-2026-61933CVE-2026-61934CVE-2026-61936CVE-2026-61937CVE-2026-61938CVE-2026-61939CVE-2026-62688CVE-2026-62690CVE-2026-62692CVE-2026-62693CVE-2026-62695CVE-2026-62696CVE-2026-62698CVE-2026-62699CVE-2026-62700CVE-2026-62701CVE-2026-62702CVE-2026-62703CVE-2026-62705CVE-2026-62707CVE-2026-62708CVE-2026-62709CVE-2026-62710CVE-2026-62711CVE-2026-62712CVE-2026-62713CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62717CVE-2026-62718CVE-2026-62719CVE-2026-62720CVE-2026-62721CVE-2026-62722CVE-2026-62723CVE-2026-62724CVE-2026-62725CVE-2026-62726CVE-2026-62728CVE-2026-62729CVE-2026-62730CVE-2026-62732CVE-2026-62733CVE-2026-62734CVE-2026-62735CVE-2026-62736CVE-2026-62737CVE-2026-62738CVE-2026-62739CVE-2026-62740CVE-2026-62741CVE-2026-62742CVE-2026-62743CVE-2026-62745CVE-2026-62746CVE-2026-62747CVE-2026-62748CVE-2026-62749CVE-2026-62750CVE-2026-62751CVE-2026-62752CVE-2026-62753CVE-2026-62754CVE-2026-62755CVE-2026-62757CVE-2026-62758CVE-2026-62761CVE-2026-62766CVE-2026-62768CVE-2026-62769CVE-2026-62770CVE-2026-62771CVE-2026-62772CVE-2026-62773CVE-2026-62774CVE-2026-62775CVE-2026-62776CVE-2026-62777CVE-2026-62778CVE-2026-62779CVE-2026-62780CVE-2026-62781CVE-2026-62782CVE-2026-62783CVE-2026-62784CVE-2026-62785CVE-2026-62786CVE-2026-62787CVE-2026-62788CVE-2026-62790CVE-2026-62792CVE-2026-62793CVE-2026-62795CVE-2026-62796CVE-2026-62797CVE-2026-62798CVE-2026-62799CVE-2026-62800CVE-2026-62803CVE-2026-62807CVE-2026-62811CVE-2026-62812CVE-2026-62814CVE-2026-62815CVE-2026-62816CVE-2026-62817CVE-2026-62818CVE-2026-62819CVE-2026-62820CVE-2026-62822CVE-2026-62823CVE-2026-62824CVE-2026-62827CVE-2026-62829CVE-2026-62830CVE-2026-62832CVE-2026-62836CVE-2026-62837CVE-2026-62839CVE-2026-62842CVE-2026-62869CVE-2026-62871CVE-2026-62872CVE-2026-62873CVE-2026-62876CVE-2026-62877CVE-2026-62878CVE-2026-62880CVE-2026-62881CVE-2026-62882CVE-2026-62883CVE-2026-62885CVE-2026-62886CVE-2026-62887CVE-2026-62888CVE-2026-62889CVE-2026-62890CVE-2026-62892CVE-2026-62893CVE-2026-62894CVE-2026-62896CVE-2026-62897CVE-2026-62898CVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62902CVE-2026-62908CVE-2026-62909CVE-2026-62910CVE-2026-62911CVE-2026-62912CVE-2026-62913CVE-2026-62914CVE-2026-62915CVE-2026-62917CVE-2026-62918CVE-2026-63508CVE-2026-63512CVE-2026-63513CVE-2026-63514CVE-2026-63515CVE-2026-63516CVE-2026-63517CVE-2026-63518CVE-2026-63519CVE-2026-63520CVE-2026-63521CVE-2026-63522CVE-2026-63524CVE-2026-63525CVE-2026-63526CVE-2026-63527CVE-2026-63528CVE-2026-63529CVE-2026-63530CVE-2026-63531CVE-2026-63532CVE-2026-63533CVE-2026-64897CVE-2026-64898CVE-2026-64899CVE-2026-64900CVE-2026-64901CVE-2026-64902CVE-2026-64903CVE-2026-64904CVE-2026-64905CVE-2026-64906CVE-2026-64907CVE-2026-64908CVE-2026-64909CVE-2026-64910CVE-2026-64911CVE-2026-64912CVE-2026-64914CVE-2026-64915CVE-2026-64916CVE-2026-64917CVE-2026-64919CVE-2026-64920CVE-2026-64921CVE-2026-64922CVE-2026-65656CVE-2026-65657CVE-2026-65658CVE-2026-65660CVE-2026-65661CVE-2026-65662CVE-2026-65663CVE-2026-65664CVE-2026-65665CVE-2026-65667CVE-2026-65668CVE-2026-65671CVE-2026-65672CVE-2026-65673CVE-2026-65675CVE-2026-65678CVE-2026-65679CVE-2026-65680CVE-2026-65681CVE-2026-65767CVE-2026-65768CVE-2026-65769CVE-2026-65773CVE-2026-65774CVE-2026-65775CVE-2026-65776CVE-2026-65777CVE-2026-65778CVE-2026-65779CVE-2026-65780CVE-2026-65781CVE-2026-65782CVE-2026-65783CVE-2026-65784CVE-2026-65785CVE-2026-65786CVE-2026-65787CVE-2026-65788CVE-2026-65789CVE-2026-65790CVE-2026-65791CVE-2026-65794CVE-2026-65795CVE-2026-65796CVE-2026-65797CVE-2026-65798CVE-2026-65799CVE-2026-65806CVE-2026-65807CVE-2026-65810CVE-2026-65811CVE-2026-65813CVE-2026-65814CVE-2026-65815CVE-2026-66301CVE-2026-66799CVE-2026-66802CVE-2026-66804CVE-2026-66805CVE-2026-66806CVE-2026-66807CVE-2026-66808CVE-2026-66809CVE-2026-66810CVE-2026-6726CVE-2026-6727CVE-2026-68792CVE-2026-68793CVE-2026-68794CVE-2026-68795CVE-2026-68796CVE-2026-68797CVE-2026-68798CVE-2026-68799CVE-2026-68800CVE-2026-68801CVE-2026-68802CVE-2026-68803CVE-2026-68804CVE-2026-68805CVE-2026-68806CVE-2026-68807CVE-2026-68808CVE-2026-68809CVE-2026-68810CVE-2026-68811CVE-2026-68812CVE-2026-68813CVE-2026-68814CVE-2026-68815CVE-2026-68816CVE-2026-68817CVE-2026-68819CVE-2026-68820CVE-2026-68821CVE-2026-68823CVE-2026-69278CVE-2026-69306CVE-2026-69320CVE-2026-70130CVE-2026-70304CVE-2026-70306CVE-2026-70307CVE-2026-70310CVE-2026-70311CVE-2026-70312CVE-2026-70313CVE-2026-70314CVE-2026-70315CVE-2026-70316CVE-2026-70317CVE-2026-70318CVE-2026-70319CVE-2026-70320CVE-2026-70321CVE-2026-70322CVE-2026-70323CVE-2026-70324CVE-2026-70325CVE-2026-70326CVE-2026-70327CVE-2026-70328CVE-2026-70329CVE-2026-70330CVE-2026-70332CVE-2026-70335CVE-2026-70336CVE-2026-70337CVE-2026-70338CVE-2026-70340CVE-2026-70344CVE-2026-70345CVE-2026-70346CVE-2026-70347CVE-2026-70348CVE-2026-70354CVE-2026-70355CVE-2026-71331CVE-2026-72971
Separate evidence group
Original

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's

CVE-2026-55040CVE-2026-63520
Separate evidence group
Original

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. Our full disclosure timeline for the exploit chain can be seen below in Figure 1. Figure 1: The road to disclosure. ⠀ CVE-2026-63520 affects all supported versions of Microsoft SharePoint. An attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. The vulnerability is due to an unsafe .NET type instantiation issue within the Business Connectivity Services . CVE-2026-63520 has a CVSSv3.1 score of 8.1 (High) , and a Common Weakness Enumeration (CWE) of CWE-20: Improper Input Validation . While the severity of the RCE is described as high, chained together with CVE-2026-55040 it becomes part of a critical unauthenticated RCE exploit chain against SharePoint. The exploit chain was developed as an entry for this year's Pwn2Own Berlin hacking competition; while our entry was unsuccessful on the day of the competition, this research highlights Rapid7 Labs' continued effort to raise the bar in Vulnerability Intelligence and our commitment to the preemptive protection of our customers through original vulnerability research. Our research methodology focused on understanding how publicly available AI models can assist in the discovery of significant vulnerabilities against proprietary enterprise targets. Our results established that the rate of model advancement is significantly accelerating vulnerability research, model guidance from subject matter experts is a force multiplier, and complex proprietary targets are easily handled through agentic workflows. On August 18, 2026, CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. Rapid7 is hosting a webinar on Thursday August 13, 2026 to discuss the research and findings for CVE-2026-55040 and CVE-2026-63520. Please join Douglas McKee and Stephen Fewer to learn more about this body of work. Workflow For this research project we wanted to understand the capabilities and limits of publicly available LLMs circa January through to March of this year. We wanted to answer the question if an AI workflow could find and develop an unauthenticated RCE exploit against a hard target such as SharePoint. This research project concluded with the successful discovery and development of such a chain. To that end, the publicly available models at the beginning of this year were indeed capable. This is notable as the rate of model improvement from Q1 of 2026 through to today has been significant. Our team's later testing of the most recent frontier models confirms the significant increase in capabilities from that of the beginning of this year. Our primary conclusion from the SharePoint research project in Q1 is that an agent guided by a subject matter expert (SME) was crucial to keep moving the model and its work towards the end goal. Given our current experience of frontier model capabilities, the need for an SME to verify and guide a model is lessened, but the compounding impact an SME can bring remains. Our first sprint in January did not result in any significant findings, rather, this sprint helped us establish the workflow and tooling that proved most useful, scope out the extremely large attack surface, and integrate prior work into our process. We augmented the agentic work with manual source code review and reverse engineering to provide additional context and steering to the model. Our early results quickly indicated how a fully automated and

CVE-2026-55040CVE-2026-63520
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.6vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.58 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-20
CPE records
3
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.