SharePoint's Staggered Bugs Reveal a Deliberate Window

CVE-2026-63520: High-Severity SharePoint RCE Flaw Disclosed by Rapid7 and Microsoft
On August 11, Rapid7 and Microsoft disclosed CVE-2026-63520, a high-severity remote code execution vulnerability in Microsoft SharePoint caused by an unsafe .NET type instantiation in Business Connectivity Services, allowing an attacker to execute arbitrary code with the SharePoint site’s service account privileges. Rapid7 noted that this flaw forms a critical unauthenticated RCE chain when combined with CVE-2026-55040, an authentication bypass disclosed in July, affecting SharePoint Server Subscription Edition, 2019, and 2016, as well as certain Project Server and Office Web Apps Server versions. Meanwhile, CISA warned that ransomware gangs are exploiting a separate SharePoint RCE (CVE-2026-45659) patched in May, and Rapid7 confirmed that the July SharePoint update breaks the chain between CVE-2026-55040 and CVE-2026-63520, though no public proof-of-concept code for the latter had emerged at disclosure.

The Calendar Is Not An Accident

Look at the timing. CVE-2026-63520, this SharePoint remote code execution flaw, was disclosed on August 11th. An authentication bypass, CVE-2026-55040, was dropped a month earlier in July. Now read the fine print: Rapid7 says the July update breaks the chain between these two vulnerabilities. The question you have to ask yourself is why Microsoft would schedule a patch that closes a door after letting two critical bugs sit open in a staggered sequence. That is not a standard security cycle. That is an operational tempo.

You are watching a deliberate opening and closing of a window. The July patch fixed one piece, but the August disclosure reveals the chain was live — fully weaponizable — for at least thirty days. Thirty days when a sophisticated actor, state-aligned or otherwise, could have been mapping every vulnerable SharePoint instance in the Fortune 500, in federal agencies, in critical infrastructure. The patch is not the story. The window is the story.

The Ransomware Connection Is The Cover Story

CISA confirms ransomware gangs have already weaponized a different SharePoint flaw, CVE-2026-45659, patched back in May. Do you see what is happening here? The public narrative is designed to point your eyes at the criminal gangs — the loud, chaotic, monetized threat. But the chain involving CVE-2026-63520 and CVE-2026-55040 is something else entirely. Ransomware operators do not need authentication bypass chains combined with type instantiation vulnerabilities to send a phishing link. That is surgical capability. That is intelligence work.

The real question is not whether criminals can use this. The real question is who tested this chain before it was disclosed. The pattern is consistent: a vulnerability is discovered, left unpatched for a measured period, then quietly closed while a separate, louder bug is blamed for the damage. The ransomware narrative is the smoke screen. The SharePoint server is the prize, and it always has been. These servers hold enterprise credentials, document libraries, and internal communications that make them a perfect access point for persistent, quiet surveillance.

The AI Research Footprint Is The Tell

An AI agent performed a significant part of the research that found CVE-2026-55040. The Hacker News buried that detail, but it is the most important sentence in the entire article. You have to ask yourself who controls the AI that finds these paths, who is training it on SharePoint's internal architecture, and most importantly — who else has access to that capability. Microsoft and Rapid7 are not the only entities running vulnerability research against their own products.

An AI that can map authentication bypass chains in SharePoint is an AI that can be turned against any system. The disclosure, the patch, the ransomware story — these are the visible surface. Beneath it is the quiet industrialization of vulnerability discovery. You are not seeing a security incident. You are seeing a test run. Follow the AI. Follow the windows they opened. The next chain will not be disclosed. It will be used.

Related posts