CVE-2026-63520
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- Published Aug 11, 2026
- CVSS 8.1 high
- 1.0% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- Revenge of the SD-WAN: Exploring and Exploiting Yet Another Critical Cisco SD-WAN Vulnerability (CVE-2026-76504) VulnCheck Blog ·
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain VulnCheck Blog ·
- Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 4 Canadian Centre for Cyber Security ·