A newly disclosed flaw in Microsoft SharePoint Server has raised fresh concerns across enterprise IT environments, as security researchers reveal how attackers could remotely inject and execute malicious code without needing any authentication. The vulnerability, tracked as CVE-2026-63520, was uncovered through a dedicated zero-day research initiative by Rapid7 Labs and has now been jointly disclosed by both Rapid7 and Microsoft. This flaw represents the second half of a two-part exploit chain that, when combined with an earlier vulnerability, CVE-2026-55040, disclosed last month, enables full unauthenticated remote code execution (RCE) on a vulnerable SharePoint server. According to Rapid7’s findings, CVE-2026-63520 affects...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!