type: cve ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [cve, rce, kev, sharepoint] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, education] ยท au_impact: true
CVE-2026-63520 โ SharePoint Business Connectivity Services RCE
CVE-2026-63520 is a remote code execution vulnerability in SharePoint's Business Connectivity Services (BCS), chained by unauthenticated attackers after the JWT bypass CVE-2026-55040 to gain code execution. An explicit copy of the PoC followed on 24 August, and chaining was observed in honeypots shortly after.
Type: Remote code execution (chained) | Mitigation: apply patch; restrict SharePoint exposure