Rapid7 and Microsoft disclose CVE-2026-63520, a new SharePoint Remote Code Execution vulnerability
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated…