Critical SharePoint Vulnerability CVE-2026-63520 Hits 2026
ID: f44bb097-7d3f-5173-8344-1425aedaaee3
STIX ID: report--f44bb097-7d3f-5173-8344-1425aedaaee3
Feed Name: CyberNexora News
**SharePoint Vulnerability CVE-2026-63520** is a newly disclosed high-severity remote code execution flaw in SharePoint's Business Connectivity Services (CVSS 8.1) that can enable arbitrary code execution with SharePoint service-account privileges and, when chained with CVE-2026-55040, create an unauthenticated RCE attack path against internet-facing SharePoint deployments; Microsoft and Rapid7 advise immediate patching, auditing of BCS usage and internet exposure, monitoring for suspicious activity, and applying least-privilege controls, while no public exploitation has been reported at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
