Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3976 articles · 226320 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-63520KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Server Remote Code Execution Vulnerability

Description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftmicrosoft sharepoint server subscription editionmitre_affected90%
microsoftmicrosoft sharepointmitre_affected90%
microsoftoutlookcert_advisory90%
microsoftofficecert_advisory90%
microsoftexcelcert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520(vendor-advisory, patch)

Related News (15 articles)

Tier C
Rapid7 Blog1h ago
SMTP is the key: BPFDoor and AVERAT hitting the network edge
→ No new info (linked only)
Tier D
Help Net Security28d ago
September 2026 Patch Tuesday forecast: All we need is more time
→ No new info (linked only)
Tier B
CERT-FR32d ago
Bulletin d'actualité CERTFR-2026-ACT-037 (31 août 2026)
→ No new info (linked only)
Tier D
The Hacker News35d ago
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
→ No new info (linked only)
Tier D
BleepingComputer36d ago
Hackers target Microsoft SharePoint RCE chain with PoC exploit
→ No new info (linked only)
Tier C
Rapid7 Blog45d ago
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
→ No new info (linked only)
Tier D
SecurityWeek50d ago
SharePoint Vulnerability Exploited Shortly After PoC Release
→ No new info (linked only)
Tier C
Rapid7 Blog51d ago
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
→ No new info (linked only)
Tier B
BSI Advisories51d ago
[NEU] [hoch] Microsoft Office Produkte: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR51d ago
Multiples vulnérabilités dans les produits Microsoft (12 août 2026)
→ No new info (linked only)
Tier C
Qualys Blog51d ago
Microsoft Patch Tuesday, August 2026 Security Update Review
→ No new info (linked only)
Tier C
Rapid7 Blog51d ago
Patch Tuesday - August 2026
→ No new info (linked only)
Tier C
VulDB51d ago
CVE-2026-63520 | Microsoft SharePoint Server input validation
→ No new info (linked only)
Tier A
Microsoft MSRC52d ago
CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability
→ No new info (linked only)
Tier C
Rapid7 Blog52d ago
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.1 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5565.100116.0.10417.2019816.0.19725.20522
CWECWE-20
PublishedAug 11, 2026
Last enriched51d ago
Trending Score142🔥
Source articles15
Independent10
Info Completeness7/14
Missing: title, description, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58644EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 167
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 167
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 160
MEDIUMCVE-2026-56164EXPKEV
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Trending: 156
HIGHCVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 61

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Added to CISA KEV
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Actively Exploited
Sep 29, 2026
Patch Available
Sep 29, 2026