DIRAS TAKE
Urgent: public exploit code is available, so apply the vendor fixes immediately or otherwise block external access to SharePoint and monitor for suspicious activity.
What is CVE-2026-63520?
An unauthenticated attacker can execute arbitrary code over a network against Microsoft SharePoint Enterprise Server 2016 (CVE-2026-63520). The issue affects Microsoft SharePoint Server 2016 (16.0.0 through before 16.0.5565.1001), SharePoint Server 2019 (16.0.0 through before 16.0.10417.20198) and SharePoint Server Subscription Edition (16.0.0 through before 16.0.19725.20522); the attacker requires only network access and no valid credentials or user interaction.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft SharePoint Enterprise Server 2016 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft SharePoint Enterprise Server 2016 16.x | 16.0.0 – before 16.0.5565.1001 | 16.0.5565.1001 |
| Microsoft SharePoint Server 2019 16.x | 16.0.0 – before 16.0.10417.20198 | 16.0.10417.20198 |
| Microsoft SharePoint Server Subscription Edition 16.x | 16.0.0 – before 16.0.19725.20522 | 16.0.19725.20522 |
Is CVE-2026-63520 being exploited?
Public exploit code is available.
How to fix CVE-2026-63520
- Install the vendor updates that contain the fixes: 16.0.5565.1001 for SharePoint 2016, 16.0.10417.20198 for SharePoint 2019, and 16.0.19725.20522 for SharePoint Subscription Edition.
- If you cannot patch immediately, restrict network exposure of SharePoint servers (block internet access, limit to trusted IPs) and disable unnecessary services.
- Monitor SharePoint logs and network traffic for anomalous requests and indicators of compromise and follow Microsoft's guidance for incident response.
Frequently asked questions
Is CVE-2026-63520 being actively exploited?
Public exploit code is available for CVE-2026-63520; there are no CISA KEV listings in the facts, but the presence of exploit code increases the risk of active exploitation.
Which Microsoft SharePoint Enterprise Server 2016 versions are affected by CVE-2026-63520?
Microsoft SharePoint Server 2016 versions from 16.0.0 up to but not including 16.0.5565.1001 are affected.
Is there a patch for CVE-2026-63520?
Yes; Microsoft published fixes: 16.0.5565.1001 for SharePoint 2016, 16.0.10417.20198 for SharePoint 2019, and 16.0.19725.20522 for SharePoint Subscription Edition.
Does CVE-2026-63520 require authentication?
No; CVE-2026-63520 can be exploited by an unauthenticated attacker with network access to the affected SharePoint product.
References
- nvd.nist.gov/vuln/detail/CVE-2026-63520
- cve.org/CVERecord?id=CVE-2026-63520
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026