SharePoint PoC Lowers the Bar for RCE

Defused says attackers are already targeting Microsoft SharePoint servers with a public proof-of-concept that chains two flaws, CVE-2026-45659 and CVE-2026-63520, into remote code execution on unpatched systems. The chain links two separate SharePoint bugs so one request opens the way for the next, ending with code running on the server. In plain terms, a normal-looking web action can turn into command execution once the two flaws are combined, which makes the attack repeatable instead of hand-crafted. That shifts the problem from a theoretical disclosure to an internet-facing access path: any exposed SharePoint host that stays unpatched can be treated as a commodity target. For operators with SharePoint in front of internal data or workflows, the exposure sits at the server layer until the vulnerable chain is removed.

Part of the PlainSec briefing for 2026-08-26

Editions

CVEs

Sources