Microsoft SharePoint RCE Flaw Chains Allow Unauthenticated Server Takeover
Brief
A newly disclosed Microsoft SharePoint Server vulnerability is raising urgent concerns for enterprise defenders after researchers demonstrated how it can be combined with an earlier flaw to enable unauthenticated remote code execution (RCE).
Tracked as CVE-2026-63520, the issue was identified by Rapid7 Labs as part of a zero-day research initiative and has been coordinated with Microsoft.
On its own, the vulnerability allows an unauthenticated remote attacker to execute code over the network under specific conditions. More significantly, researchers said it forms the second stage of an exploit chain with CVE-2026-55040, a SharePoint vulnerability disclosed in July 2026 .
