CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
B Rapid7 Cybersecurity Blog · · CVE-2026-63520 , CVE-2026-55040
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 8.1
- EPSS
- 40%
Affected versions
Key insight
Unsafe .NET type instantiation in Business Connectivity Services enables remote code execution with SharePoint service account privileges; developed as a Pwn2Own entry and affects all supported SharePoint versions.
Description
The vulnerability CVE-2026-63520 exists in unsafe .NET type instantiation within Microsoft SharePoint's Business Connectivity Services (BCS). An attacker can exploit this flaw to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site service account. The vulnerability was discovered by Rapid7 Labs and developed as an entry for the Pwn2Own Berlin hacking competition. All currently supported versions of Microsoft SharePoint are affected. The CVE has been patched at the time of disclosure (marked as FIXED).
Risk score
- cvss base
- 81.00
- kev bonus
- 20.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 116.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 28.00
- vendor mismatch penalty
- 0.00
Path: operational