CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our…
KEV ✓ EPSS 0.04 CVSS 8.1 CVE-2026-55040 CVE-2026-63520 Microsoft veřejná správa finance US