ZeroHour

CVE-2026-20963

KEVmass

Deserialization RCE in Microsoft SharePoint Exploited in the Wild

CISA: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
33%p98
Published
()
KEV added
AI analysis

CVE-2026-20963 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint that allows an unauthorized attacker to execute code remotely over the network. The flaw is triggered when SharePoint processes maliciously crafted serialized data without validating it, enabling an attacker to run arbitrary code in the context of the SharePoint service. Successful exploitation gives the attacker code execution on the affected SharePoint server, a foothold that typically supports further lateral movement and data access within the environment. Organizations running affected SharePoint deployments are in scope, though affected version ranges have not yet been published in the available data. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-18, confirming active exploitation, and its EPSS of 31.6% (98th percentile) indicates a high near-term probability of exploitation; no public proof-of-concept is known and CVSS scoring is not yet available.

What to do: Inventory all SharePoint deployments, prioritize any internet-facing SharePoint Server instances, and apply Microsoft's security updates or vendor-specified mitigations as soon as they are available; federal agencies must follow BOD 22-01 (including cloud services) with its standard remediation timeline, and others should treat KEV inclusion as a patch-now signal despite the absence of a public PoC. Until patched, restrict network exposure of SharePoint and review server logs for signs of untrusted serialized data being processed leading to unexpected code execution.

Affected
Microsoft SharePoint
Estimated exposure
massOrder of millions of users across plausibly hundreds of thousands of SharePoint deployments (SharePoint Online and on-prem SharePoint Server) — SharePoint is one of the most widely deployed collaboration platforms — SharePoint Online is bundled with Microsoft 365 used by tens of millions of users and SharePoint Server has a very large on-premises and government install base —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CISA Known Exploited Vulnerability
Affected
Microsoft SharePoint
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
sharepoint server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

2026-004: Critical Vulnerability in SharePoint Exploited

CVE-2026-20963 (CVSS 9.8), an unauthenticated RCE in on-prem SharePoint, was added to CISA's KEV on 18 March 2026 and is actively exploited.

CERT-EU warns about CVE-2026-20963, a CVSS 9.8 unauthenticated remote code execution flaw in SharePoint caused by deserialisation of untrusted data, affecting SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Microsoft raised the CVSS score on 17 March 2026 and the flaw entered CISA's Known Exploited Vulnerabilities catalogue on 18 March 2026. Three additional SharePoint RCE flaws (CVE-2026-26106, CVE-2026-26113, CVE-2026-26114) were fixed in the March 2026 release. CERT-EU urges immediate patching of internet-facing servers plus AMSI Full Mode, EDR deployment, ASP.NET machine key rotation, and compromise assessments.

CERT-EU Advisories · Mar 25, 2026Exploit / PoC in the wildCVE-2026-20963CVE-2026-26106CVE-2026-26113+1 CVEs