Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Imported from official source

Cybersecurity Classified by Officially

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

On August 11, 2026, Rapid7 and Microsoft disclosed CVE-2026-63520, a remote code execution (RCE) vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of CVE-2026-63520. This analysis was originally scheduled for publication 30 days after disclosure; however, as a third party has published details of CVE-2026-63520, our timeline has been expedited.

A remote authenticated attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. When combined with the authentication bypass, CVE-2026-55040, the resulting exploit chain is unauthenticated RCE against a vulnerable SharePoint server.

When comparing the two analysis of CVE-2026-63520, we can see how we have exploited the issue by leveraging a Database Line-of-Business (LOB) system and an ObjectDataProvider based gadget chain, whilst the VulnCheck analysis has exploited the issue by leveraging a DotNetAssembly LOB system and a LosFormatter based gadget chain. Defenders should account for this when detecting CVE-2026-63520. It is highly likely other gadget chains may also be used.

The following technical analysis is based upon SharePoint Server Subscription Edition version 16.0.19725.20210.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520

Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Rapid7 — imported from official source
Official source
https://blog.rapid7.com/rss/ RSS
Imported
September 18, 2026 11:35
Versions
1 recorded
Identity
blt5f90657fff716e5d

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.