THE Rapid7 blog post discusses the recently fixed vulnerability CVE-2026-63520, a Remote Code Execution (RCE) flaw in Microsoft SharePoint discovered through research by Rapid7 Labs. The vulnerability can be exploited to execute arbitrary code on affected SharePoint servers. It is the second in a chain with CVE-2026-55040, which is an authentication bypass vulnerability. Both issues were disclosed collaboratively between Rapid7 and Microsoft, with the first flaw disclosed previously.
The RCE vulnerability has a CVSSv3.1 score of 8.1 (High) and can allow an attacker to perform significant operations with the service account's privileges. Rapid7 will host a webinar on August 13, 2026, covering these findings, and customers are advised to apply updates to protect against the vulnerabilities. The article also includes a detailed disclosure timeline and technical analysis.