Vulnerability
Published 2026-08-11
Verified 2026-09-19

Microsoft SharePoint Server remote code execution (CVE-2026-63520)

Microsoft's 11 August 2026 Patch Tuesday fix (MSRC CVE-2026-63520) addresses improper input validation in on-premises SharePoint that lets an unauthorised attacker execute code over the network. NVD scores it 8.1 (CVSS 3.1, High, attack complexity High). Rapid7, which co-disclosed with Microsoft, says the bug is unsafe .NET type instantiation in Business Connectivity Services and that chaining it with the July auth bypass CVE-2026-55040 yields unauthenticated RCE. August security updates cover SharePoint Server Subscription Edition (KB5002893), SharePoint Server 2019 (KB5002894 / KB5002896), and SharePoint Enterprise Server 2016 (KB5002905 / KB5002906). Public PoC material for the RCE half appeared around 24 August; Defused later reported honeypot probes of the 55040+63520 chain (JWT bypass exercised, BCS probing, no code execution observed in that report). Microsoft had not labelled 63520 as exploited in the wild at last magazine check. Prefer the August updates; do not leave on-prem SharePoint internet-facing without need.

Product
Microsoft SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016)
Versions
Supported on-prem SharePoint builds before the August 2026 security updates listed in MSRC / Rapid7 remediation table
CVSS
(CVSS 3.1, NVD High)
Exploited in Australia?
unknown
Patch to
KB5002893 (Subscription Edition); KB5002894/KB5002896 (2019); KB5002905/KB5002906 (2016). Also patch CVE-2026-55040 if not already

Primary: Microsoft MSRC (CVE-2026-63520) · Vendor: Microsoft Security Update Guide · CVE: CVE-2026-63520, CVE-2026-55040 · Rapid7 coordinated disclosure (11 Aug 2026)

vulnerabilities