CVE-2026-63520
published 2026-08-11CVE-2026-63520: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
PriorityP183high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
2.89%
86.0th percentile
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5565.1001 | 16.0.5565.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20198 | 16.0.10417.20198 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19725.20522 | 16.0.19725.20522 |
| microsoft | sharepoint_server | < 16.0.19725.20522 | 16.0.19725.20522 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
ghsa_unreviewed·2026-08-11
CVE-2026-63520 [HIGH] CWE-20 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
VulnCheck
Microsoft SharePoint Improper Input Validation
vulncheck·2026·CVSS 8.1
CVE-2026-63520 [HIGH] Microsoft SharePoint Improper Input Validation
Microsoft SharePoint Improper Input Validation
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Affected: Microsoft SharePoint
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://x.com/DefusedCyber/status/2092228764323217723
No detection rules found.
No public exploits indexed.
Hackernews
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
blogs_hackernews·2026-08-27
CVE-2026-55040 ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different tricks, same advantage: attackers keep finding places where trust is cheap and friction is low.
That sets the tone. Here’s the full list o
Rapid7
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
blogs_rapid7·2026-08-24·CVSS 8.8
CVE-2026-63520 [HIGH] Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
## Overview
On August 11, 2026, Rapid7 and Microsoft disclosed CVE-2026-63520, a remote code execution (RCE) vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of CVE-2026-63520. This analysis was originally scheduled for publication 30 days after disclosure; however, as a third party has published details of CVE-2026-63520, our timeline has been expedited.
A remote authenticated attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. When combined with the authentication bypass, CVE-2026-55040 , the resulting exploit chain is unauthenticated RCE against a vulnerable SharePoint server.
Database
ObjectDataProvider
DotNetAssembly
LosFormatter
#
Hackernews
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
blogs_hackernews·2026-08-12·CVSS 7.0
CVE-2026-68820 [HIGH] Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.
The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft ha
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Rapid7
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
blogs_rapid7·2026-08-11·CVSS 9.1
CVE-2026-63520 [CRITICAL] CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
## Overview
Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.
Our full disclosure timeline for the exploit chain can be seen below in Figure 1.
Figure 1: The road to disclosure.
⠀
CVE-2026-63520 affects all supported versions of Microsoft SharePoint, and certain versions of Microsoft Project Server and Microsoft Office Web Apps Server. For the purpose of our
Tenable
Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
blogs_tenable·2026-08-11·CVSS 7.0
CVE-2026-68820 [HIGH] Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
## Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
42 Critical
355 Important
1 Moderate
0 Low
Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.
Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.
This month’s update includes patches for:
.NET
.NET Core
.NET Framework
AMD Zen
Active Directory Certificate Services (AD CS)
Application Information Services
Azure Active Directory
Azure CycleCloud
Azure Monitor Agent
Azure Storage Explorer
Capability Access Management Service (camsvc)
Desktop Window M
Qualys
Microsoft Patch Tuesday, August 2026 Security Update Review
blogs_qualys·2026-08-11
CVE-2026-72971 Microsoft Patch Tuesday, August 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forAugust2026
Zero-day Vulnerabilities Patched inAugustPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inAugustPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security.
## Microsoft Patch Tuesday for August 2026
This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities.
In this month’s updates, Microsof
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Talos
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-08-11·CVSS 9.4
CVE-2026-68820 [CRITICAL] Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild
CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.0.
Out of 62 "critical" vulnerabilities, 40 are remote code execution (RCE) vulnerabilities.
Microsoft considers exploitation of the following vulnerabilities more lik
Hackernews
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
blogs_hackernews·2026-08-11·CVSS 9.1
CVE-2026-55040 [CRITICAL] Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.
The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them.
It lets a remote unauthenticated attacker assume a chosen user's
2026-08-11
Published
Exploited in the wild