Remote Code Execution Vulnerability in Microsoft Office SharePoint
CVE-2026-63520

8.1HIGH

Key Information:

Badges

๐Ÿ“ˆ Score: 953๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐Ÿ“ฐ News Worthy

What is CVE-2026-63520?

CVE-2026-63520 is a vulnerability affecting Microsoft Office SharePoint, a widely used collaboration platform that facilitates document management, storage, and sharing within organizations. The vulnerability arises from improper input validation, allowing unauthorized attackers to execute arbitrary code over a network. This could lead to numerous adverse scenarios, including unauthorized data access and control over the affected SharePoint server, jeopardizing sensitive organizational data. Given the centrality of SharePoint in many enterprises for organizing and storing critical documents, the exploitation of this vulnerability could disrupt business operations and lead to severe information security breaches.

Potential impact of CVE-2026-63520

  1. Unauthorized Code Execution: The primary risk associated with CVE-2026-63520 is the potential for attackers to execute malicious code remotely. This action can lead to unauthorized access to sensitive data stored in SharePoint, enabling attackers to manipulate, steal, or delete critical organizational information.

  2. Data Breach and Loss: The execution of arbitrary code can result in significant data breaches. Once an attacker gains control, they could exfiltrate confidential data or introduce malware into the environment, posing a severe threat to corporate privacy and compliance with data protection regulations.

  3. Operational Disruption: Organizations relying on SharePoint for their operations may face major disruptions due to the exploitation of this vulnerability. Attacks could lead to downtime, loss of productivity, and a subsequent financial impact, complicating recovery efforts and restoring normal operations.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5565.1001

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20198

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20522

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Microsoft SharePoint Exploit Chain: Why the Latest RCE Flaw Matters

Microsoft SharePoint is under active attack via an exploit chain that combines authentication bypass and RCE flaws. Hereโ€™s what organizations need to know.

5 days ago

Two SharePoint Flaws Give Hackers a Path to Remote Code Execution

Hackers are probing a Microsoft SharePoint exploit chain that combines CVE-2026-55040 and CVE-2026-63520 for potential remote code execution.

1 week ago

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.

1 week ago

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Cyber Risk Leaders

  • Vulnerability published

  • Vulnerability Reserved

.