A newly disclosed flaw in Microsoft SharePoint Server has rekindled concerns among enterprise IT departments, as security researchers unveil how attackers can remotely inject and execute malicious code without requiring any authentication. The vulnerability, identified as CVE-2026-63520, was discovered through a dedicated zero-day research initiative by Rapid7 Labs, which has now been jointly announced by both Rapid7 and Microsoft. This flaw constitutes the second part of a two-part exploit chain that, when combined with an earlier vulnerability disclosed last month, enables full unauthenticated remote code execution (RCE) on a vulnerable SharePoint server.
According to Rapid7’s findings, CVE-2026-63520 affects all currently supported versions of Microsoft SharePoint, along with select versions of Microsoft Project Server and Microsoft Office Web Apps Server, though the research team's testing focused specifically on SharePoint deployments. This poses significant risks for organizations using internet-facing or improperly segmented SharePoint servers, as it could provide threat actors with direct access to sensitive document repositories, intranet systems, and connected enterprise applications. Rapid7 researcher Stephen Fewer highlighted the significance of chained vulnerability analysis in uncovering deeper architectural flaws within widely used enterprise platforms.
Organizations are advised to immediately audit their SharePoint deployments, verify patch levels, and monitor for unusual Business Connectivity Services activity as a preventive measure against potential future exploitation.












