Microsoft SharePoint Vulnerabilities Allow Unauthenticated RCE
Rapid7 Labs has disclosed two new vulnerabilities in Microsoft SharePoint that allow for unauthenticated remote code execution (RCE) when chained together. The second vulnerability, CVE-2026-63520, affects all supported versions of Microsoft SharePoint and certain versions of Project Server and Office Web Apps Server.
The exploit chain was developed as an entry for the Pwn2Own Berlin hacking competition, where Rapid7's entry was unsuccessful on the day of the competition. However, this research highlights Rapid7's continued effort to raise the bar in Vulnerability Intelligence and their commitment to the preemptive protection of customers through original vulnerability research.
The RCE vulnerability, CVE-2026-63520, has a CVSSv3.1 score of 8.1 (High) and allows an attacker to execute arbitrary code on an affected server with the privileges of the SharePoint Site's service account. The vulnerability is due to an unsafe .NET type instantiation issue within the Business Connectivity Services.
Rapid7 will be hosting a webinar on August 13, 2026, to discuss the research and findings for CVE-2026-55040 and CVE-2026-63520.