CVE-2026-63520
As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure Confidential Ledger Azure CycleCloud Azure Kubernetes Service Azure Logic Apps Azure Monitor Agent Linux Extension Azure SQL Database Azure SQL Managed Instance Azure SRE Agent Azure Service Bus Azure Storage Explorer Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Admin Center Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Defender for Endpoint for Mac Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Business Central 2024 Microsoft Dynamics 365 Business Central 2026 Microsoft Dynamics 365 Business Central Release Wave 1 2025 Microsoft Dynamics 365 Business Central Release Wave 2 2025 Microsoft Entra Connect Microsoft Entra ID Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Outlook 2016 Microsoft Planetary Computer Pro (GeoCatalog) Microsoft Power Apps Microsoft PowerPoint 2016 Microsoft Purview eDiscovery Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Online Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft Teams Microsoft Teams for Android Microsoft Teams for iOS Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Microsoft Visual Studio Code CoPilot Chat Extension Microsoft Word 2016 OneDrive for MacOS Power BI Report Server PowerShell 7.4 PowerShell 7.5 PowerShell 7.6 Python extension for Visual Studio Code Visual Studio Code Windows 10 Windows 11 Windows App Client for Windows Desktop Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025 The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations, and apply the necessary updates. Update 1 On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-33824 and CVE-2026-55040 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-63520 related to Microsoft SharePoint Server is being exploited in the wild.
EPSS 2.89% · 85.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Azure | Azure Logic Apps | |
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | |
| Microsoft | Microsoft Office LTSC 2024 | |
| Microsoft | .NET 9.0 installed on Windows | |
| Microsoft | Windows Server 2025 | |
| Microsoft | Microsoft Excel 2016 | |
| Azure | Azure Confidential Ledger | |
| Microsoft | .NET 10.0 installed on Windows | |
| Microsoft | Microsoft Office 2019 | |
| Microsoft | Microsoft SharePoint Server 2019 | |
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | |
| OneDrive | OneDrive for MacOS | |
| Microsoft | Windows 11 | |
| .NET | .NET 10.0 installed on Linux | |
| .NET | .NET 8.0 installed on Linux | |
| Microsoft | Microsoft SharePoint Online | |
| Azure | Azure SQL Database | |
| Microsoft | Microsoft Office 2016 | |
| Microsoft | Microsoft Dynamics 365 Business Central Release Wave 1 2025 | |
| .NET | .NET 8.0 installed on Mac OS |
…and 65 more
Timeline
- Aug 11, 2026 CVE Published
- Aug 12, 2026 Coalition ESS Score
- Aug 15, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 EPSS Score
- Sep 4, 2026 Security Advisory
References
- https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804 advisory
- https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040 advisory