Critical cybersecurity update: CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED). The report references CVE-2026-55040, CVE-2026-63520. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.
What Happened
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month. ⠀ CVE-2026-63520 affects all supported versions of Microsoft SharePoint, and certain versions of Microsoft Project Server and Microsoft Office Web Apps Server. An attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. While the severity of the RCE is described as high, chained together with CVE-2026-55040 it becomes part of a critical unauthenticated RCE exploit chain against SharePoint. Rapid7 is hosting a webinar on Thursday August 13, 2026 to discuss the research and findings for CVE-2026-55040 and CVE-2026-63520. An authentication bypass, now known as CVE-2026-55040, was discovered and verified in early March, followed two weeks later by the RCE, now known as CVE-2026-63520.
Technical Details
The vulnerability identifiers associated with this report are CVE-2026-55040, CVE-2026-63520. Product descriptions The RCE vulnerability, CVE-2026-63520, affects SharePoint, Project Server, and Office Web Apps Server, while the authentication bypass vulnerability, CVE-2026-55040, affects only SharePoint. Impact CVE-2026-63520 allows an attacker to execute arbitrary code on an affected server. As CVE-2026-63520 can be chained to the authentication bypass vulnerability, CVE-2026-55040, the resulting exploit chain allows for unauthenticated RCE against a vulnerable server. Vendor statement The following statement has been provided by Microsoft: “We would like to thank Rapid7 for responsibly reporting this issue through coordinated vulnerability disclosure.” Technical analysis Rapid7 will be publishing full technical details for the RCE vulnerability, CVE-2026-63520, within 30 days of this disclosure. The technical details for the authentication bypass vulnerability, CVE-2026-55040, have been published here . Remediation The following products are impacted by CVE-2026-63520: Microsoft SharePoint Server Subscription Edition SharePoint Server Subscription Edition Language Pack Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2016 Microsoft Project Server 2013 Service Pack 1 (64-bit edition) Microsoft Office Web Apps 2013 Service Pack 1 Customers are advised to apply the latest available updates for the impacted product to ensure they are protected. Rapid7 customers Exposure Command, InsightVM, and Nexpose Exposure Command, InsightVM and Nexpose customers will be able to assess their exposure to the RCE vulnerability, CVE-2026-63520, with authenticated vulnerability checks available in the August 12 content release. Customers can assess their exposure to the authentication bypass vulnerability, CVE-2026-55040, with authenticated vulnerability checks available in the July 15 content release. May 20, 2026: Microsoft confirms the findings and indicates that the exploit chain will be patched across two scheduled update cycles – the authentication bypass component in July, and the RCE component in August.
Security Impact
Organizations using the affected technology should treat the report according to its critical severity classification. The presence of a tracked CVE gives defenders a concrete identifier to use when checking vendor advisories, vulnerability scanners, asset inventories and patch-management systems. Rapid7 and Microsoft disclose CVE-2026-63520, a new SharePoint Remote Code Execution vulnerability Aug 11, 2026 | Last updated on Aug 11, 2026 | 8 min read Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. The RCE vulnerability, CVE-2026-63520, affects SharePoint, Project Server, and Office Web Apps Server, while the authentication bypass vulnerability, CVE-2026-55040, affects only SharePoint. CVE-2026-63520 allows an attacker to execute arbitrary code on an affected server. The following statement has been provided by Microsoft: “We would like to thank Rapid7 for responsibly reporting this issue through coordinated vulnerability disclosure.” Rapid7 will be publishing full technical details for the RCE vulnerability, CVE-2026-63520, within 30 days of this disclosure. Exposure Command, InsightVM and Nexpose customers will be able to assess their exposure to the RCE vulnerability, CVE-2026-63520, with authenticated vulnerability checks available in the August 12 content release. Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
Recommended Actions
- Identify whether the affected product, service or software is present in the environment.
- Review the original vendor or research advisory and verify affected versions before making configuration changes.
- Apply vendor-provided security updates or mitigations as soon as operationally practical.
- Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
- Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.
Security Details
- Severity: Critical
- CVE: CVE-2026-55040, CVE-2026-63520
- CISA KEV: No match detected in the current catalog.
- Original source: Rapid7
Why This Matters
Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.
Original Report
NetworkFix recommends reviewing the complete original report from Rapid7 for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.