Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

See all Threat Responses

Dutch follows English

The SharePoint Server vulnerability CVE-2026-63520, disclosed and patched by Microsoft on 14 July 2026, is now beingactively exploited in the wild [1][2]. When combined with CVE-2026-55040, this vulnerability can be leveraged as part of a critical unauthenticated remote code execution exploit chain [3]. Due to ongoing exploitation activity, Northwave recommends immediate action.

Description
After discovery by Rapid7, Microsoft has disclosed and patched a vulnerability in SharePoint Server identified as CVE-2026-63520 [3]. While this vulnerability alone may not result in unauthenticated remote code execution, it can be combined with CVE-2026-55040 as part of an exploit chain that enables an attacker to execute arbitrary code on a vulnerable SharePoint server without authentication. Successful exploitation of this chain can lead to full compromise of the affected system. Active exploitation of this vulnerability chain by threat actors targeting internet-exposed SharePoint environments has also been documented in CISA's Known Exploited Vulnerabilities (KEV) catalog [4].

Impact
We estimate the impact of this vulnerability as high.

An attacker who successfully exploits the vulnerability chain involving CVE-2026-63520 and CVE-2026-55040 can execute malicious code on the affected SharePoint server, potentially leading to unauthorized access to sensitive data, modification of content, installation of malware, lateral movement within the network, and complete compromise of the underlying system. As SharePoint often stores business-critical information, the potential business impact can be significant.

Risk
We estimate the risk of this vulnerability as high.

The NCSC has stated that CVE-2026-63520 is being actively exploited in real-world attacks. Organizations with internet-facing SharePoint servers are at the highest risk, particularly if systems remain unpatched against both vulnerabilities that form the exploit chain. Due to active exploitation and the critical role SharePoint plays within many organizations, we consider this a high-priority security issue requiring immediate attention.

Mitigation
Microsoft has released security updates that address CVE-2026-63520 and related vulnerabilities. Organizations should install the latest SharePoint security updates as soon as possible to mitigate the risk of exploitation through the known attack chain. Detailed guidance and update information can be found through Microsoft's Security Response Center:

https://portal.msrc.microsoft.com/en-us/security-guidance

Organizations should prioritize patching all SharePoint servers, especially systems that are accessible from the internet. In addition, review network access controls and limit exposure of SharePoint environments wherever possible.

What should you do?
Install the available Microsoft security updates as soon as possible, prioritizing SharePoint servers, particularly internet-facing installations, due to active exploitation. Ensure that all patches addressing both CVE-2026-63520 and CVE-2026-55040 are applied, as attackers may leverage these vulnerabilities together as part of an exploit chain. Test and deploy patches according to your organization's change management procedures, but expedite the process given the ongoing attacks.

If immediate patching is not possible, Northwave recommends restricting access to SharePoint servers to trusted networks and administrators only. Additionally, review SharePoint and related system logs for signs of suspicious activity, unauthorized access, or indicators of compromise. If you are unsure you are compromised, we recommend to contact the Northwave CERT for assistance.

What will Northwave do?
We will monitor any developments regarding these vulnerabilities. If new critical information about this threat arises, we will reach out to you. You can contact us by phone or send us an email if you would like additional information.

 


E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000

Disclaimer applies, see below.

Sources

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528

[2] https://advisories.ncsc.nl/2026/ncsc-2026-0286.html

[3] https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed/

[4] https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations

 


De SharePoint Server-kwetsbaarheid CVE-2026-63520, die door Microsoft op 14 juli 2026 is gepubliceerd en gepatcht, wordt nu actief misbruikt in aanvallen [1][2]. In combinatie met CVE-2026-55040 kan deze kwetsbaarheid worden gebruikt als onderdeel van een kritieke exploitketen voor unauthenticated remote code execution [3]. Vanwege de lopende misbruikactiviteiten adviseert Northwave om direct actie te ondernemen.

Beschrijving
Na ontdekking door Rapid7 heeft Microsoft een kwetsbaarheid in SharePoint Server, geïdentificeerd als CVE-2026-63520, gepubliceerd en verholpen [3]. Hoewel deze kwetsbaarheid op zichzelf mogelijk niet leidt tot unauthenticated remote code execution, kan zij in combinatie met CVE-2026-55040 worden gebruikt als onderdeel van een exploitketen waarmee een aanvaller zonder authenticatie willekeurige code kan uitvoeren op een kwetsbare SharePoint-server. Succesvolle exploitatie van deze keten kan leiden tot volledige compromittering van het getroffen systeem. Actieve exploitatie van deze kwetsbaarheidsketen door dreigingsactoren die zich richten op via internet bereikbare SharePoint-omgevingen is tevens gedocumenteerd in de Known Exploited Vulnerabilities (KEV)-catalogus van CISA [4].

Impact
Wij schatten de impact van deze kwetsbaarheid in als hoog.

Een aanvaller die de exploitketen met CVE-2026-63520 en CVE-2026-55040 succesvol misbruikt, kan kwaadaardige code uitvoeren op de getroffen SharePoint-server. Dit kan leiden tot ongeautoriseerde toegang tot gevoelige gegevens, wijziging van content, installatie van malware, laterale verplaatsing binnen het netwerk en volledige compromittering van het onderliggende systeem. Omdat SharePoint vaak bedrijfskritische informatie bevat, kan de potentiële bedrijfsimpact aanzienlijk zijn.

Risico
Wij schatten het risico van deze kwetsbaarheid in als hoog.

Het NCSC heeft aangegeven dat CVE-2026-63520 actief wordt misbruikt in aanvallen in de praktijk. Organisaties met internettoegankelijke SharePoint-servers lopen het grootste risico, met name wanneer systemen niet zijn gepatcht tegen beide kwetsbaarheden die samen de exploitketen vormen. Vanwege het actieve misbruik en de kritieke rol die SharePoint binnen veel organisaties vervult, beschouwen wij dit als een beveiligingsprobleem met hoge prioriteit dat onmiddellijke aandacht vereist.

Mitigatie
Microsoft heeft beveiligingsupdates uitgebracht die CVE-2026-63520 en gerelateerde kwetsbaarheden verhelpen. Organisaties dienen de meest recente beveiligingsupdates voor SharePoint zo snel mogelijk te installeren om het risico op misbruik via de bekende exploitketen te beperken. Gedetailleerde informatie en update-instructies zijn beschikbaar via het Microsoft Security Response Center:

https://portal.msrc.microsoft.com/en-us/security-guidance

Organisaties dienen prioriteit te geven aan het patchen van alle SharePoint-servers, in het bijzonder systemen die via internet bereikbaar zijn. Daarnaast adviseren wij om netwerktoegangscontroles te beoordelen en de blootstelling van SharePoint-omgevingen waar mogelijk te beperken.

Wat moet u doen?
Installeer de beschikbare Microsoft-beveiligingsupdates zo snel mogelijk en geef daarbij prioriteit aan SharePoint-servers, met name internettoegankelijke installaties, vanwege het actieve misbruik. Zorg ervoor dat alle patches voor zowel CVE-2026-63520 als CVE-2026-55040 worden toegepast, aangezien aanvallers deze kwetsbaarheden gecombineerd kunnen gebruiken als onderdeel van een exploitketen. Test en implementeer patches conform de wijzigingsprocedures van uw organisatie, maar versnel dit proces gezien de lopende aanvallen.

Indien direct patchen niet mogelijk is, adviseert Northwave om de toegang tot SharePoint-servers te beperken tot uitsluitend vertrouwde netwerken en beheerders. Daarnaast raden wij aan SharePoint- en gerelateerde systeemlogs te controleren op verdachte activiteiten, ongeautoriseerde toegang of andere indicatoren van compromittering. Als u niet zeker weet of u bent gecompromitteerd, raden wij u aan contact op te nemen met het Northwave CERT voor ondersteuning.

Wat doet Northwave?
Wij blijven de ontwikkelingen rondom deze kwetsbaarheden monitoren. Indien er nieuwe kritieke informatie over deze dreiging beschikbaar komt, nemen wij contact met u op. Voor aanvullende informatie kunt u telefonisch of per e-mail contact met ons opnemen.

E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000

Disclaimer van toepassing, zie onderaan.

Bronnen

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528

[2] https://advisories.ncsc.nl/2026/ncsc-2026-0286.html

[3] https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed/

[4] https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations

 

Disclaimer

Northwave has made every effort to make this information accurate and reliable. However, the information provided is without warranty of any kind and its use is at the sole risk of the user. Northwave does not accept any responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided. We will not be liable for any loss or damage of whatever nature, direct or indirect, consequential or other, whether arising in contract, tort or otherwise, which may arise as a result of your use of, or inability to use, this information or any additional information provided by us in direct or indirect relation to the information provided here.
.