RAPID7 CYBERSECURITY BLOG
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
MEDIUM CVE-2026-63520 SharePoint RCE authentication-bypass
Strategic summary
RCE vulnerability in Microsoft SharePoint allows authenticated attackers to execute arbitrary code; exploit details reveal XML-based Business Data Catalog manipulation as the attack vector.
Relevance for you
RCE vulnerability in Microsoft SharePoint allows authenticated attackers to execute arbitrary code; exploit details reveal XML-based Business Data Catalog manipulation as the attack vector.
Mentioned CVEs
Risk score
55
- cvss base
- 81.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 96.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 15.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -3.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
CVE_ABSENTTitle-claimed CVE missing from description −3
- Consensus penalty:
- −3.0
- Total penalty:
- −3.0