A critical SharePoint remote code execution (RCE) vulnerability has been identified as CVE-2026-63520, alongside an authentication bypass flaw (CVE-2026-55040). Both vulnerabilities have been exploited in the wild, posing a significant threat to organizations using Microsoft SharePoint Enterprise Server 2016 and other supported versions. Immediate updates are required to prevent potential attacks. The CVSS score of CVE-2026-55040 is 9.1, while CVE-2026-63520 has a score of 8.1.
Microsoft recommends users update to specific versions to mitigate risks. Attackers can execute commands under SharePoint’s service account privileges through a crafted model file, leveraging these vulnerabilities together. Defenders are advised to monitor network activity and restrict access to administrative endpoints until patches are applied.