THREAT OPS › Threat News › CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style="font-size: undefined;">Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disc
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-63520cve
- CVE-2026-55040cve
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:Curl
- https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-resultsurl
- https://www.brighttalk.com/webcast/10457/673829?utm_source=blog&utm_medium=website&utm_content=microsoft-sharepoint-webinar&utm_campaign=na-vrm-q3-2026-global-webinar-prospect-eng-etos-25url
- images.contentstack.iodomain