Microsoft SharePoint Server remote code execution (CVE-2026-63520)
Microsoft's 11 August 2026 Patch Tuesday fix (MSRC CVE-2026-63520) addresses improper input validation in on-premises SharePoint that lets an unauthorised attacker execute code over the network. NVD scores it 8.1 (CVSS 3.1, High, attack complexity High). Rapid7, which co-disclosed with Microsoft, says the bug is unsafe .NET type instantiation in Business Connectivity Services and that chaining it with the July auth bypass CVE-2026-55040 yields unauthenticated RCE. August security updates cover SharePoint Server Subscription Edition (KB5002893), SharePoint Server 2019 (KB5002894 / KB5002896), and SharePoint Enterprise Server 2016 (KB5002905 / KB5002906). Public PoC material for the RCE half appeared around 24 August; Defused later reported honeypot probes of the 55040+63520 chain (JWT bypass exercised, BCS probing, no code execution observed in that report). Microsoft had not labelled 63520 as exploited in the wild at last magazine check. Prefer the August updates; do not leave on-prem SharePoint internet-facing without need.
- Product
- Microsoft SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016)
- Versions
- Supported on-prem SharePoint builds before the August 2026 security updates listed in MSRC / Rapid7 remediation table
- CVSS
- (CVSS 3.1, NVD High)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- KB5002893 (Subscription Edition); KB5002894/KB5002896 (2019); KB5002905/KB5002906 (2016). Also patch CVE-2026-55040 if not already
Primary: Microsoft MSRC (CVE-2026-63520) · Vendor: Microsoft Security Update Guide · CVE: CVE-2026-63520, CVE-2026-55040 · Rapid7 coordinated disclosure (11 Aug 2026)
