Threat Advisory

Microsoft SharePoint Server Flaw Lets Attackers Execute Malicious Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Microsoft SharePoint Server, affecting all currently supported versions, along with select versions of Microsoft Project Server and Microsoft Office Web Apps Server. The overall risk/impact is significant, allowing remote code execution without authentication, posing a threat to organizations running internet-facing or improperly segmented SharePoint servers.

CVE-2026-63520 (CVSS X.X — Severity): An attacker can execute arbitrary code with the privileges of the SharePoint Site’s service account by exploiting an unsafe.NET type instantiation issue within SharePoint’s Business Connectivity Services. This allows for a foothold deep inside an organization’s internal infrastructure without valid credentials.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Microsoft SharePoint Server, affecting all currently supported versions, along with select versions of Microsoft Project Server and Microsoft Office Web Apps Server. The overall risk/impact is significant, allowing remote code execution without authentication, posing a threat to organizations running internet-facing or improperly segmented SharePoint servers.

CVE-2026-63520 (CVSS X.X — Severity): An attacker can execute arbitrary code with the privileges of the SharePoint Site’s service account by exploiting an unsafe.NET type instantiation issue within SharePoint’s Business Connectivity Services. This allows for a foothold deep inside an organization’s internal infrastructure without valid credentials.[emaillocker id="1283"]

CVE-2026-55040: When combined with CVE-2026-63520, this vulnerability enables full unauthenticated remote code execution on a vulnerable SharePoint server. These vulnerabilities collectively present a significant risk to organizations running Microsoft SharePoint Server. Administrators should apply every available security update associated with this advisory and audit their SharePoint deployments immediately. These vulnerabilities collectively present a significant risk to organizations running Microsoft SharePoint Server.

These vulnerabilities collectively present a significant risk to organizations running Microsoft SharePoint Server.

RECOMMENDATION:

We recommend you to update Microsoft SharePoint Server to given version link: https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed/

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu