CVE-2026-63520 carries a CVSS 3.1 base score of 8.1 against Microsoft SharePoint. NVD classifies it as CWE-20 (Improper Input Validation). VulnCheck’s KEV feed reports the CVE as exploited, dated August 25, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-63520 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description is brief: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. NVD does not name the specific input field or code path involved beyond that summary; Microsoft’s own security advisory, linked from NVD’s record, is the authoritative technical source, but our source data does not carry deeper mechanism detail from it.
We report NVD’s classification as stated rather than speculating about the missing technical detail behind a description this brief.
Evidence and confidence
- Medium confidence — the CVSS 8.1 score, the vector (
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), and the CWE-20 classification, which trace to NVD alone in our current ingestion. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.02893, an 86.2nd percentile score as of our ingestion — notably high for a VulnCheck-only listing.
No field is in conflict between our two sources. Our data carries no fixed-version field; consult Microsoft’s own security advisory directly for patch guidance.
Why this matters
SharePoint deployments are frequently internet-facing collaboration hubs holding substantial organizational document and identity data, making an unauthenticated remote-code-execution-class flaw a high-value target regardless of the sparse public technical detail available so far. The 86th-percentile EPSS score, notably high for a listing that isn’t yet CISA-corroborated, suggests meaningful exploitation activity or interest is already building around this CVE even without a formal CISA confirmation.
Because the exploitation report is VulnCheck-only, treat it as a credible but single-sourced signal warranting prompt attention rather than a confirmed, catalog-verified compromise campaign — the high EPSS percentile is a reason to prioritize patching now rather than wait for further corroboration.
Frequently Asked Questions
What is CVE-2026-63520? A CVSS 8.1 improper input validation vulnerability (CWE-20) in Microsoft SharePoint, allowing an unauthorized attacker to execute code over a network.
Is CVE-2026-63520 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 25, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Does an attacker need an account to exploit this?
No. The CVSS vector indicates no privileges are required (PR:N), per NVD’s classification, though attack complexity is rated high.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our data carries no fixed-version field. Consult Microsoft’s own security advisory directly for the specific patch matching your SharePoint version.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-63520. Microsoft’s own security advisory: MSRC guidance for CVE-2026-63520. Exploitation status and the August 25, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.