Microsoft: Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

Microsoft: Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

Critical SharePoint Server Flaw Enables Unauthenticated Remote Code Execution

Security researchers at Rapid7 Labs have disclosed a severe vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, which allows attackers to execute malicious code remotely without authentication. The flaw, part of a two-part exploit chain alongside CVE-2026-55040 (disclosed last month), enables full unauthenticated remote code execution (RCE) on vulnerable systems.

The vulnerability stems from an unsafe .NET type instantiation issue in SharePoint’s Business Connectivity Services, a component that integrates external data sources. Exploitation grants attackers the privileges of the SharePoint service account, providing deep access to internal infrastructure, document repositories, and connected enterprise applications. Microsoft’s assessment confirms improper input validation as the root cause, making internet-facing or poorly segmented SharePoint servers particularly high-risk targets.

Affected systems include all supported versions of Microsoft SharePoint Server, as well as select versions of Microsoft Project Server and Office Web Apps Server, though testing focused primarily on SharePoint. While no active exploitation or public proof-of-concept code exists, Microsoft rates the flaw as "exploitation more likely" due to its potential impact. However, successful attacks require precise technical conditions, as the CVSS scoring indicates high attack complexity.

Microsoft has released security updates to address the vulnerability, with patch requirements varying by SharePoint version. Notably, SharePoint Server 2016 and SharePoint Enterprise Server 2016 share the same update package. Organizations are advised to apply all relevant patches immediately, as this marks the second critical SharePoint flaw disclosed from Rapid7’s research in under a month.

Rapid7 researcher Stephen Fewer, who discovered the vulnerability, highlighted the importance of chained vulnerability analysis in uncovering deeper architectural weaknesses in enterprise platforms. Security teams are encouraged to audit SharePoint deployments, verify patch levels, and monitor Business Connectivity Services for suspicious activity.

Source: https://cybersecuritynews.com/microsoft-sharepoint-server-vulnerability/

Microsoft_SharePoint cybersecurity rating report: https://www.rankiteo.com/company/microsoft_sharepoint

"id": "MIC1786515825",
"linkid": "microsoft_sharepoint",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Software',
                        'name': 'Microsoft',
                        'type': 'Technology'}],
 'attack_vector': 'Network',
 'description': 'Security researchers at Rapid7 Labs have disclosed a severe '
                'vulnerability in Microsoft SharePoint Server, tracked as '
                'CVE-2026-63520, which allows attackers to execute malicious '
                'code remotely without authentication. The flaw, part of a '
                'two-part exploit chain alongside CVE-2026-55040, enables full '
                'unauthenticated remote code execution (RCE) on vulnerable '
                'systems. The vulnerability stems from an unsafe .NET type '
                'instantiation issue in SharePoint’s Business Connectivity '
                'Services, granting attackers the privileges of the SharePoint '
                'service account.',
 'impact': {'operational_impact': 'Deep access to internal infrastructure, '
                                  'document repositories, and connected '
                                  'enterprise applications',
            'systems_affected': 'Microsoft SharePoint Server, Microsoft '
                                'Project Server, Office Web Apps Server'},
 'lessons_learned': 'Importance of chained vulnerability analysis in '
                    'uncovering deeper architectural weaknesses in enterprise '
                    'platforms',
 'post_incident_analysis': {'corrective_actions': 'Apply security updates, '
                                                  'audit deployments, enhance '
                                                  'monitoring',
                            'root_causes': 'Improper input validation in '
                                           'SharePoint’s Business Connectivity '
                                           'Services'},
 'recommendations': 'Apply all relevant patches immediately, audit SharePoint '
                    'deployments, verify patch levels, and monitor Business '
                    'Connectivity Services for suspicious activity',
 'references': [{'source': 'Rapid7 Labs'}],
 'response': {'containment_measures': 'Apply security updates/patches',
              'enhanced_monitoring': 'Monitor Business Connectivity Services '
                                     'for suspicious activity',
              'network_segmentation': 'Recommended for poorly segmented '
                                      'SharePoint servers',
              'remediation_measures': 'Audit SharePoint deployments, verify '
                                      'patch levels, monitor Business '
                                      'Connectivity Services for suspicious '
                                      'activity'},
 'title': 'Critical SharePoint Server Flaw Enables Unauthenticated Remote Code '
          'Execution',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': ['CVE-2026-63520', 'CVE-2026-55040']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.