CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

2026-08-11T19:23:37Z85c31bf913f8dc5b2af8475feac3bc1ae0541d6a8890ad1424875634ca61e293
CVE-2026-18556CVE-2026-18577CVE-2026-55040CVE-2026-63077CVE-2026-63520CVE-2026-66066JetBrains TeamCityMicrosoft SharePointN-able N-centralRuby on Railsactive-exploitationarbitrary-file-readauthentication-bypassknown-exploited-vulnerabilitypatchingremote-code-executionunauthenticated-exploitationunsafe-deserializationvulnerability

What happened

Rapid7 reports several significant vulnerabilities, including unauthenticated remote code execution in Microsoft SharePoint (CVE-2026-63520) chained with an authentication bypass (CVE-2026-55040), unauthenticated unsafe-deserialization RCE in JetBrains TeamCity (CVE-2026-63077) confirmed in CISA KEV, authentication bypass and administrative takeover of N-able N-central (CVE-2026-18577) exploited in the wild, and arbitrary file read with potential RCE in Ruby on Rails Active Storage (CVE-2026-66066).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
85c31bf913f8dc5b2af8475feac3bc1ae0541d6a8890ad1424875634ca61e293
Enrichment time
2026-08-11T19:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED) · Baitaphish