Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Cybersecurity Classified by Officially
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
On August 11, 2026, Rapid7 and Microsoft disclosed CVE-2026-63520, a remote code execution (RCE) vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of CVE-2026-63520. This analysis was originally scheduled for publication 30 days after disclosure; however, as a third party has published details of CVE-2026-63520, our timeline has been expedited.
A remote authenticated attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. When combined with the authentication bypass, CVE-2026-55040, the resulting exploit chain is unauthenticated RCE against a vulnerable SharePoint server.
When comparing the two analysis of CVE-2026-63520, we can see how we have exploited the issue by leveraging a Database Line-of-Business (LOB) system and an ObjectDataProvider based gadget chain, whilst the VulnCheck analysis has exploited the issue by leveraging a DotNetAssembly LOB system and a LosFormatter based gadget chain. Defenders should account for this when detecting CVE-2026-63520. It is highly likely other gadget chains may also be used.
The following technical analysis is based upon SharePoint Server Subscription Edition version 16.0.19725.20210.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Rapid7 — imported from official source
- Official source
- https://blog.rapid7.com/rss/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
blt5f90657fff716e5d