
🛡️ **CRITICAL: Microsoft SharePoint Zero-Day RCE Chain Disclosed**
Published Tuesday, August 11, 2026 at 10:28 AM PT BLUF: Rapid7 and Microsoft today disclosed CVE-2026-63520 (remote code execution), the second vulnerability in a two-bug chain affecting Microsoft SharePoint. When chained with CVE-2026-55040, attackers can achieve unauthenticated RCE on vulnerable instances. Immediate action: Identify all SharePoint deployments; obtain patch status from Microsoft immediately; isolation/network segmentation for production instances pending patches. DETAILS Rapid7 Labs zero-day research identified two SharePoint vulnerabilities that chain to achieve unauthenticated remote code execution. First CVE (CVE-2026-55040) disclosed previously by Rapid7 and Microsoft; second CVE (CVE-2026-63520) disclosed today concurrent with this alert. Attack chain does not require prior authentication; no valid user account needed to trigger RCE. Vulnerability affects Microsoft SharePoint (specific versions not yet detailed in available disclosures). Exploitation risk is elevated: Rapid7 has functional research code demonstrating the chain. UNCONFIRMED: Active in-the-wild exploitation; patch availability and timeline; affected SharePoint product versions (on-premises vs. online). IMPACT ...





