cognitive cybersecurity intelligence

News and Analysis

Search

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely

A newly disclosed flaw in Microsoft SharePoint Server has raised fresh concerns across enterprise IT environments, as security researchers reveal how attackers could remotely inject and execute malicious code without needing any authentication.

The vulnerability, tracked as CVE-2026-63520, was uncovered through a dedicated zero-day research initiative by Rapid7 Labs and has now been jointly disclosed by both Rapid7 and Microsoft.

This flaw represents the second half of a two-part exploit chain that, when combined with an earlier vulnerability, CVE-2026-55040, disclosed last month, enables full unauthenticated remote code execution (RCE) on a vulnerable SharePoint server.

According to Rapid7’s findings, CVE-2026-63520 affects all currently supported versions of Microsoft SharePoint, along with select versions of Microsoft Project Server and Microsoft Office Web Apps Server, though the research team’s testing focused specifically on SharePoint deployments.

Microsoft SharePoint Server Vulnerability

The root cause lies in an unsafe .NET type instantiation issue within SharePoint’s Business Connectivity Services, a component that allows SharePoint to interact with external data sources.

By exploiting this weakness, an attacker can execute arbitrary code with the privileges of the SharePoint Site’s service account, effectively gaining a foothold deep inside an organization’s internal infrastructure without ever needing valid credentials.

Microsoft’s executive summary describes the issue plainly: improper input validation in Office SharePoint allows an unauthorized attacker to execute code over a network.

This makes the vulnerability particularly dangerous for organizations running internet-facing or improperly segmented SharePoint servers, since a successful attack chain could give threat actors a direct pathway into sensitive document repositories, intranet systems, and connected enterprise applications.

As of the disclosure date, CVE-2026-63520 has not been publicly exploited, and no proof-of-concept code is circulating, though Microsoft’s exploitability assessment rates it as “exploitation more likely,” signaling that attackers could weaponize it soon.

Notably, the CVSS scoring for this flaw lists a high attack complexity, meaning that exploitation isn’t trivial. Attackers would need to meet precise technical conditions and invest significant effort to reliably chain CVE-2026-55040 and CVE-2026-63520 together for full remote code execution.

For organizations managing on-premises SharePoint environments, Microsoft strongly advises applying every available security update associated with this advisory, since multiple update packages may apply depending on the specific SharePoint version in use.

Updates can be installed in any order, but all relevant patches must be applied to achieve complete protection. Notably, administrators running either SharePoint Server 2016 or SharePoint Enterprise Server 2016 can rely on the same KB update package, as both versions share identical patch requirements.

Given that this marks the second vulnerability disclosed from the same research effort within a month, security teams should treat SharePoint patch management as an urgent priority.

Rapid7 researcher Stephen Fewer, credited with the discovery, emphasized the importance of chained vulnerability analysis in exposing deeper architectural weaknesses within widely used enterprise platforms.

Organizations are urged to audit their SharePoint deployments immediately, verify patch levels, and monitor for anomalous Business Connectivity Services activity as a precaution against potential future exploitation.

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
The post Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts