CVE-2026-63520: SharePoint RCE Chain Probed in the Wild, PoC Public
ID: 308452b6-36fd-5b74-a482-44e3ffbba06d
STIX ID: report--308452b6-36fd-5b74-a482-44e3ffbba06d
Feed Name: securityonline.info
Threat Score
**Critical SharePoint RCE chain (CVE-2026-63520 + CVE-2026-55040)** — Proof-of-concept exploit code and technical details have been published and threat actors are actively probing/exploiting on-premises SharePoint servers; unauthenticated remote code execution is achievable when the RCE is chained with an authentication bypass, affecting multiple supported SharePoint Server builds and requiring immediate application of Microsoft’s security updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
