www.rapid7.com 8/25/2026, 12:11:02 AM · external

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Developing story vulnerability 24 articles tracked
Multiple actively exploited vulnerabilities disclosed in August 2026
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

RAPID 7's analysis of CVE-2026-63520 highlights a significant remote code execution (RCE) vulnerability in Microsoft SharePoint. This flaw, disclosed on August 11, 2026, allows an authenticated attacker to execute arbitrary code with the privileges of the SharePoint service account. The analysis describes the technical details of exploiting this vulnerability using unsafe .NET type instantiation in the Business Data Connectivity (BDC) subsystem.

It details methods used to bypass authentication and execute attacks, including a walkthrough showcasing HTTP requests necessary for triggering unsafe type instantiation. The findings emphasize the importance of understanding potential gadget chains and defensive measures.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline