Rapid7 and Microsoft disclosed CVE-2026-63520, a high-severity remote code execution flaw in Microsoft SharePoint that can be chained with the previously disclosed authentication bypass CVE-2026-55040 to achieve unauthenticated RCE on vulnerable on-premises SharePoint servers. The chain affects supported SharePoint versions and also impacts certain versions of Microsoft Project Server and Microsoft Office Web Apps Server, with the initial authentication bypass also reported to affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft advised customers to apply the latest updates, and Rapid7 said July updates disrupted the exploit chain while the RCE fix was disclosed separately.
Rapid7 said CVE-2026-55040 lets attackers forge JWTs and impersonate SharePoint users or administrators by exploiting multiple weaknesses in SharePoint's token validation pipeline, including inadequate signature enforcement and certificate validation. Attackers can obtain the SharePoint STS signing certificate from an unauthenticated metadata endpoint, craft forged nested JWTs, and access authenticated endpoints before using CVE-2026-63520 in Business Connectivity Services, where unsafe .NET type instantiation enables arbitrary code execution under the SharePoint Site service account. Researchers said the exploit chain was developed during a zero-day research project using AI-assisted workflows, while noting that expert oversight was required throughout the discovery process.

See affected versions and whether adversaries are exploiting it.
18 events from the most recent confirmed update back to the earliest known activity.
Defused observed attackers probing its SharePoint honeypots with the CVE-2026-55040 authentication bypass followed by administrator enumeration and probing of the CVE-2026-63520 Business Data Catalog sink. Defused did not observe successful remote code execution from this activity.
Rapid7 published a technical analysis of CVE-2026-63520 describing how SharePoint's Business Data Connectivity subsystem can instantiate attacker-controlled .NET types from BDC model XML to achieve code execution. The write-up demonstrated an exploitation path using an ObjectDataProvider gadget chain and noted that third-party publication had expedited release of the analysis.
CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog after exploitation was observed following public disclosure. The listing marked the SharePoint authentication bypass as an officially tracked exploited vulnerability.
After Rapid7 published its proof-of-concept for CVE-2026-55040, Defused reported that attackers had already weaponized it and were using it against SharePoint honeypots. The activity indicated rapid attempted exploitation following public technical disclosure, even though Microsoft had not yet marked the flaw as exploited in the wild.
Rapid7 published a technical analysis and proof-of-concept for CVE-2026-55040, detailing weaknesses in SharePoint's JWT validation pipeline and showing forged authentication to SharePoint endpoints.
Rapid7 and Microsoft disclosed CVE-2026-63520 on August 11, 2026, describing a high-severity SharePoint remote code execution flaw that can be chained with CVE-2026-55040 for unauthenticated RCE.
Microsoft released August security updates for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 to address the vulnerabilities that can be chained for unauthenticated server compromise. SharePoint Online was not affected.
SharePoint Server 2016 and SharePoint Server 2019 reached end of support on July 14, creating uncertainty about future security updates for affected deployments.
On July 14, CISA said CVE-2026-55040 was not yet known to have been exploited, while also warning that other SharePoint flaws were under active exploitation.
Rapid7 and Microsoft disclosed CVE-2026-55040, a SharePoint JWT authentication bypass that lets unauthenticated attackers impersonate users or administrators.
Microsoft shipped July server updates for SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 that Rapid7 said break the exploit chain.
Rapid7 agreed to a 30-day stay on publishing technical details unless in-the-wild exploitation or third-party publication occurred earlier.
Microsoft confirmed Rapid7's findings and said the exploit chain would be patched across two scheduled update cycles, with the authentication bypass addressed in July and the RCE in August.
Rapid7 disclosed the unauthenticated SharePoint RCE exploit chain to Microsoft through coordinated vulnerability disclosure.
Rapid7 discovered CVE-2026-63520 approximately two weeks after finding CVE-2026-55040, identifying the RCE component of the SharePoint exploit chain.
Rapid7 said its March 2026 research sprint produced a two-vulnerability exploit path to unauthenticated SharePoint compromise with AI-assisted analysis.
Rapid7 discovered and verified the SharePoint authentication bypass CVE-2026-55040 in early March 2026 during its SharePoint research.
Rapid7 conducted a research sprint against the SharePoint codebase in January 2026, but said it did not produce a usable exploit chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcedecipher.sc
Open sourcerapid7.com
Open sourcerapid7.com
Open sourcegithub.com
Open sourcecve.org
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.