Rapid7 and Microsoft disclose SharePoint RCE flaw CVE-2026-63520

0

Rapid7 Labs says it has identified two new vulnerabilities in Microsoft SharePoint that can be chained to achieve unauthenticated remote code execution (RCE) on a vulnerable server.

On Wednesday, Rapid7 and Microsoft disclosed the second issue in the chain: CVE-2026-63520, which Rapid7 described as an RCE vulnerability.

The first vulnerability, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month and was described by Rapid7 as a Microsoft SharePoint JWT token authentication bypass. Rapid7 said it has also published a technical analysis of CVE-2026-55040 by Rapid7 Labs researcher Stephen Fewer.

Rapid7’s write-up of CVE-2026-63520 and related details are available on the company’s blog.

Share.