Skip to content
Auto-CTI
Back to today
KEV NEW HIGH B1

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

B Rapid7 Cybersecurity Blog · · CVE-2026-63520 , CVE-2026-55040

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
8.1
EPSS
40%

Affected versions

sharepoint server sharepoint server 2016 sharepoint server 2019

Key insight

Unsafe .NET type instantiation in Business Connectivity Services enables remote code execution with SharePoint service account privileges; developed as a Pwn2Own entry and affects all supported SharePoint versions.

Description

The vulnerability CVE-2026-63520 exists in unsafe .NET type instantiation within Microsoft SharePoint's Business Connectivity Services (BCS). An attacker can exploit this flaw to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site service account. The vulnerability was discovered by Rapid7 Labs and developed as an entry for the Pwn2Own Berlin hacking competition. All currently supported versions of Microsoft SharePoint are affected. The CVE has been patched at the time of disclosure (marked as FIXED).

Risk score

70
cvss base
81.00
kev bonus
20.00
epss bonus
0.00
poc bonus
15.00
raw before weight
116.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
28.00
vendor mismatch penalty
0.00

Path: operational

ESC