Junglewise Threat Intelligence

CVE-2026-63520: Microsoft Office SharePoint code execution via improper input validation

CVE-2026-63520 · Severity: high · CVSS 8.1 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint is a widely-deployed collaboration platform used by enterprises to manage documents and team content. An improper input validation vulnerability allows an attacker to execute arbitrary code on servers hosting SharePoint without authentication, potentially leading to data theft, system compromise, or disruption of critical business operations across an entire organization.

Technical details

This vulnerability stems from improper input validation in Microsoft Office SharePoint that fails to adequately sanitize or validate user-supplied input before processing. An attacker can exploit this flaw by sending a specially crafted network request to trigger remote code execution on the affected SharePoint server. The attack is unauthenticated and network-accessible, requiring no prior access or user interaction. Successful exploitation allows an attacker to execute arbitrary code with SharePoint service privileges, potentially enabling full server compromise, lateral movement, or data exfiltration.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-08-11: disclosed

References

Related threats