Remote Code Execution Vulnerability in Microsoft Office SharePoint
CVE-2026-63520
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-63520?
CVE-2026-63520 is a vulnerability affecting Microsoft Office SharePoint, a widely used collaboration platform that facilitates document management, storage, and sharing within organizations. The vulnerability arises from improper input validation, allowing unauthorized attackers to execute arbitrary code over a network. This could lead to numerous adverse scenarios, including unauthorized data access and control over the affected SharePoint server, jeopardizing sensitive organizational data. Given the centrality of SharePoint in many enterprises for organizing and storing critical documents, the exploitation of this vulnerability could disrupt business operations and lead to severe information security breaches.
Potential impact of CVE-2026-63520
-
Unauthorized Code Execution: The primary risk associated with CVE-2026-63520 is the potential for attackers to execute malicious code remotely. This action can lead to unauthorized access to sensitive data stored in SharePoint, enabling attackers to manipulate, steal, or delete critical organizational information.
-
Data Breach and Loss: The execution of arbitrary code can result in significant data breaches. Once an attacker gains control, they could exfiltrate confidential data or introduce malware into the environment, posing a severe threat to corporate privacy and compliance with data protection regulations.
-
Operational Disruption: Organizations relying on SharePoint for their operations may face major disruptions due to the exploitation of this vulnerability. Attacks could lead to downtime, loss of productivity, and a subsequent financial impact, complicating recovery efforts and restoring normal operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5565.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20198
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20522
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Microsoft SharePoint Exploit Chain: Why the Latest RCE Flaw Matters
Microsoft SharePoint is under active attack via an exploit chain that combines authentication bypass and RCE flaws. Hereโs what organizations need to know.
5 days ago
Two SharePoint Flaws Give Hackers a Path to Remote Code Execution
Hackers are probing a Microsoft SharePoint exploit chain that combines CVE-2026-55040 and CVE-2026-63520 for potential remote code execution.
1 week ago
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.
1 week ago
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by Cyber Risk Leaders
Vulnerability published
Vulnerability Reserved