🟠 High | Source: Microsoft Security Response Center
CVE-2026-63512 is a tampering vulnerability in Microsoft SharePoint Server caused by incorrect authorisation controls. An already-authenticated attacker can exploit this flaw over a network to manipulate SharePoint data or configuration without proper permission. Organisations relying on SharePoint for document management and collaboration are at risk of unauthorised data modification.
Security Architect’s Take: Apply Microsoft’s patch immediately and review SharePoint access controls to ensure least-privilege principles are enforced; consider temporarily restricting external network access to SharePoint Server instances until patching is confirmed across all nodes.
Original advisory: CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability