CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
2026-08-11T19:23:37Z•85c31bf913f8dc5b2af8475feac3bc1ae0541d6a8890ad1424875634ca61e293
CVE-2026-18556CVE-2026-18577CVE-2026-55040CVE-2026-63077CVE-2026-63520CVE-2026-66066JetBrains TeamCityMicrosoft SharePointN-able N-centralRuby on Railsactive-exploitationarbitrary-file-readauthentication-bypassknown-exploited-vulnerabilitypatchingremote-code-executionunauthenticated-exploitationunsafe-deserializationvulnerability
What happened
Rapid7 reports several significant vulnerabilities, including unauthenticated remote code execution in Microsoft SharePoint (CVE-2026-63520) chained with an authentication bypass (CVE-2026-55040), unauthenticated unsafe-deserialization RCE in JetBrains TeamCity (CVE-2026-63077) confirmed in CISA KEV, authentication bypass and administrative takeover of N-able N-central (CVE-2026-18577) exploited in the wild, and arbitrary file read with potential RCE in Ruby on Rails Active Storage (CVE-2026-66066).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 85c31bf913f8dc5b2af8475feac3bc1ae0541d6a8890ad1424875634ca61e293
- Enrichment time
- 2026-08-11T19:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.