← Back to the CVE Tracker
Rapid7 has published a technical analysis of CVE-2026-63520, a critical remote code execution vulnerability in Microsoft SharePoint. The vulnerability allows an authenticated attacker to execute arbitrary code on a vulnerable server by uploading a malicious BDC model file. When combined with another vulnerability, CVE-2026-55040, it can lead to unauthenticated RCE.