25 August 2026
Reference: CVE-2026-63520
1. What is being reported?
Researchers have identified a problem in Microsoft SharePoint where it does not properly check user input. This weakness could allow someone who is not authorised to run malicious code on your network through SharePoint.
2. What this means in plain English
If your organisation uses Microsoft SharePoint, this vulnerability could let attackers take control of your SharePoint system remotely. This could lead to data theft, disruption of services, or further attacks on your network.
3. Could this affect a small business?
Small businesses that use Microsoft SharePoint, especially those hosting it themselves or using certain configurations, could be affected. If you only use SharePoint through a managed cloud service, your provider may have already applied protections, but you should confirm this.
4. What to do now
- Check with your IT provider or software supplier if your SharePoint system is affected by this vulnerability.
- Apply any security updates or patches provided by Microsoft as soon as they become available.
- Review who has access to your SharePoint system and limit permissions to only those who need it.
- Monitor your SharePoint environment for any unusual activity and report concerns promptly.
5. Ask your IT provider
Can you confirm if our Microsoft SharePoint system is affected by CVE-2026-63520, and what steps have been taken to protect us?
6. Bottom line
If you use Microsoft SharePoint, act quickly to check and secure your system against this serious vulnerability.
Information based on CISA KEV, NVD, and reputable security reporting.