Rapid7 Labs says it has identified two new vulnerabilities in Microsoft SharePoint that can be chained to achieve unauthenticated remote code execution (RCE) on a vulnerable server.
On Wednesday, Rapid7 and Microsoft disclosed the second issue in the chain: CVE-2026-63520, which Rapid7 described as an RCE vulnerability.
The first vulnerability, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month and was described by Rapid7 as a Microsoft SharePoint JWT token authentication bypass. Rapid7 said it has also published a technical analysis of CVE-2026-55040 by Rapid7 Labs researcher Stephen Fewer.
Rapid7’s write-up of CVE-2026-63520 and related details are available on the company’s blog.

