Remote Code Execution Vulnerability in Microsoft Office SharePoint
CVE-2026-63520
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-63520?
CVE-2026-63520 is a vulnerability affecting Microsoft Office SharePoint, a widely used collaboration platform that facilitates document management, storage, and sharing within organizations. The vulnerability arises from improper input validation, allowing unauthorized attackers to execute arbitrary code over a network. This could lead to numerous adverse scenarios, including unauthorized data access and control over the affected SharePoint server, jeopardizing sensitive organizational data. Given the centrality of SharePoint in many enterprises for organizing and storing critical documents, the exploitation of this vulnerability could disrupt business operations and lead to severe information security breaches.
Potential impact of CVE-2026-63520
-
Unauthorized Code Execution: The primary risk associated with CVE-2026-63520 is the potential for attackers to execute malicious code remotely. This action can lead to unauthorized access to sensitive data stored in SharePoint, enabling attackers to manipulate, steal, or delete critical organizational information.
-
Data Breach and Loss: The execution of arbitrary code can result in significant data breaches. Once an attacker gains control, they could exfiltrate confidential data or introduce malware into the environment, posing a severe threat to corporate privacy and compliance with data protection regulations.
-
Operational Disruption: Organizations relying on SharePoint for their operations may face major disruptions due to the exploitation of this vulnerability. Attacks could lead to downtime, loss of productivity, and a subsequent financial impact, complicating recovery efforts and restoring normal operations.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5565.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20198
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20522
News Articles
Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely
A critical remote code execution flaw in Microsoft SharePoint Server that, when chained with a previously reported authentication bypass, lets an attacker take over a vulnerable server without ever needing valid credentials.
2 days ago

Rapid7 and Microsoft disclose SharePoint RCE flaw CVE-2026-63520
Rapid7 Labs says it has identified two new vulnerabilities in Microsoft SharePoint that can be chained to achieve unauthenticated remote code execution (RCE) on a vulnerable server.
2 days ago
References
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by Cyber Risk Leaders
Vulnerability published
Vulnerability Reserved