Vulnerability intelligence
CVE-2026-63520
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS Score
8.1
High
EPSS — Exploit Probability
1.0%
Riskier than 60% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
5 articles across 3 outlets · first covered Aug 11, 2026 · latest Aug 25, 2026
Coverage timeline
-
Critical SharePoint RCE and Auth Bypass Flaws Actively Exploitedsecurityonline.info · Aug 25, 2026
-
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)www.rapid7.com · Aug 25, 2026
-
SharePoint Auth Bypass Flaw CVE-2026-55040 Under Active Attackwww.securityweek.com · Aug 12, 2026
-
Microsoft Fixes 421 Flaws Including SharePoint Zero Daywww.rapid7.com · Aug 12, 2026
-
Rapid7 Finds Critical SharePoint RCE Flaw Tied to Auth Bypasswww.rapid7.com · Aug 11, 2026