Critical Microsoft SharePoint Server CVE-2023-29357 Lets Attackers Remotely Execute Code
Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-63520, has been disclosed in Microsoft SharePoint Server. The flaw allows unauthenticated attackers to execute arbitrary...
Key Takeaways
- A critical remote code execution (RCE) vulnerability, CVE-2026-63520, has been disclosed in Microsoft SharePoint Server.
- The flaw allows unauthenticated attackers to execute arbitrary code with service account privileges.
- It affects all supported versions of Microsoft SharePoint, Project Server, and Office Web Apps Server.
- The vulnerability is part of a two-stage exploit chain, requiring CVE-2026-55040 for full RCE.
- Microsoft has released patches, and immediate application is strongly recommended.
Unauthenticated RCE Poses Grave Threat to Microsoft SharePoint Servers
A severe security vulnerability in Microsoft SharePoint Server has come to light, enabling attackers to remotely execute arbitrary code on affected systems without requiring any form of authentication. This critical flaw, identified as CVE-2026-63520, has ignited significant concern across organizations utilizing SharePoint for critical business operations.
Table Of Content
Discovered through a focused zero-day research initiative by Rapid7 Labs, the vulnerability was jointly disclosed by Rapid7 and Microsoft. This marks the second component of a sophisticated two-part exploit chain. When combined with a previously disclosed flaw, CVE-2026-55040, it facilitates complete unauthenticated remote code execution on vulnerable SharePoint servers.
According to Rapid7’s findings, CVE-2026-63520 impacts all currently supported iterations of Microsoft SharePoint, in addition to specific versions of Microsoft Project Server and Microsoft Office Web Apps Server. While the research primarily focused on SharePoint deployments, the broader implications for these related products are clear.
Technical Details of the SharePoint Flaw
The core of the vulnerability resides in an unsafe .NET type instantiation within SharePoint’s Business Connectivity Services (BCS). This component is designed to facilitate SharePoint’s interaction with external data sources. Exploitation of this weakness grants an attacker the ability to execute arbitrary code, operating with the privileges of the SharePoint Site’s service account. This provides a deep foothold within an organization’s internal infrastructure without the need for valid credentials, bypassing traditional security barriers.
Microsoft’s executive summary succinctly describes the problem as “Improper input validation in Office SharePoint allows an unauthorized attacker to execute code over a network.” This makes the vulnerability particularly dangerous for organizations that expose SharePoint servers to the internet or have inadequate network segmentation. A successful attack could provide threat actors with direct access to sensitive document repositories, intranet systems, and interconnected enterprise applications.
As of its disclosure, CVE-2026-63520 has not been observed in public exploitation, and no proof-of-concept code is currently available. However, Microsoft’s exploitability assessment rates it as “exploitation more likely,” indicating a strong potential for its weaponization by attackers in the near future.
The CVSS score for this vulnerability notes a high attack complexity, meaning exploitation is not trivial. Attackers would need to fulfill specific technical prerequisites and invest substantial effort to reliably chain CVE-2026-55040 and CVE-2026-63520 to achieve full remote code execution.
Urgent Patching Recommended
For organizations managing on-premises SharePoint environments, Microsoft strongly advises the immediate application of all relevant security updates associated with this advisory. Multiple update packages may be necessary, depending on the specific SharePoint version in use. While updates can be installed in any order, administrators must apply all applicable patches to achieve complete protection. Notably, SharePoint Server 2016 and SharePoint Enterprise Server 2016 share identical patch requirements, utilizing the same KB update package.
Given that this represents the second vulnerability disclosed from the same research effort within a single month, security teams must prioritize SharePoint patch management. Rapid7 researcher Stephen Fewer, who is credited with the discovery, underscored the critical importance of analyzing chained vulnerabilities to uncover deeper architectural weaknesses in widely adopted enterprise platforms.
What You Should Do
- Apply Patches Immediately: Prioritize and install all security updates released by Microsoft for CVE-2026-63520 across all affected SharePoint, Project Server, and Office Web Apps Server instances.
- Verify Patch Levels: After applying updates, thoroughly verify that all relevant patches have been successfully installed and are active.
- Audit SharePoint Deployments: Conduct an immediate audit of all SharePoint deployments, especially those internet-facing, to understand their exposure.
- Monitor for Anomalous Activity: Implement and monitor for any unusual or suspicious activity originating from Business Connectivity Services as a preventative measure against potential future exploitation attempts.
- Review Network Segmentation: Ensure proper network segmentation is in place to limit the lateral movement of attackers should a compromise occur.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.