logo

CVE-2026-63520: SharePoint RCE Chain Probed in the Wild, PoC Public

ID: 308452b6-36fd-5b74-a482-44e3ffbba06d

STIX ID: report--308452b6-36fd-5b74-a482-44e3ffbba06d

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

Author: Do Son

...
...

**Critical SharePoint RCE chain (CVE-2026-63520 + CVE-2026-55040)** — Proof-of-concept exploit code and technical details have been published and threat actors are actively probing/exploiting on-premises SharePoint servers; unauthenticated remote code execution is achievable when the RCE is chained with an authentication bypass, affecting multiple supported SharePoint Server builds and requiring immediate application of Microsoft’s security updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.