ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)

highVulnerability exploited in the wildimportance 60CVE-2026-20963

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20963
Deserialization RCE in Microsoft SharePoint Exploited in the Wild

CVE-2026-20963 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint that allows an unauthorized attacker to execute code remotely over the network. The flaw is triggered when SharePoint processes maliciously crafted serialized data without validating it, enabling an attacker to run arbitrary code in the context of the SharePoint service. Successful exploitation gives the attacker code execution on the affected SharePoint server, a foothold that typically supports further lateral movement and data access within the environment. Organizations running affected SharePoint deployments are in scope, though affected version ranges have not yet been published in the available data. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-18, confirming active exploitation, and its EPSS of 31.6% (98th percentile) indicates a high near-term probability of exploitation; no public proof-of-concept is known and CVSS scoring is not yet available.

Do: Inventory all SharePoint deployments, prioritize any internet-facing SharePoint Server instances, and apply Microsoft's security updates or vendor-specified mitigations as soon as they are available; federal agencies must follow BOD 22-01 (including cloud services) with its standard remediation timeline, and others should treat KEV inclusion as a patch-now signal despite the absence of a public PoC. Until patched, restrict network exposure of SharePoint and review server logs for signs of untrusted serialized data being processed leading to unexpected code execution.

9.833% KEV
  • Microsoft SharePoint
massOrder of millions of users across plausibly hundreds of thousands of SharePoint deployments (SharePoint Online and on-prem SharePoint Server)
Full article301 words · extracted from helpnetsecurity.com · click to collapse

CVE-2026-20963, a remote code execution (RCE) SharePoint vulnerability Microsoft fixed in January 2026, is being exploited by attackers.

SharePoint CVE-2026-20963 exploited

The confirmation comes from the US Cybersecurity and Infrastructure Security Agency (CISA), which added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday.

About CVE-2026-20963

CVE-2026-20963 affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, and Microsoft SharePoint Enterprise Server 2016.

It is caused by deserialization of untrusted data and may allow an unauthorized attacker to achieve RCE through a low-complexity attack.

“In a network-based attack, an unauthenticated attacker could write arbitrary code to inject and execute code remotely on the SharePoint Server,” Microsoft explained in the related security advisory published on January 13, 2026.

No user interaction is required for CVE-2026-20963 exploitation.

At the time of the release of the fix, Microsoft judged the vulnerability as “less likely” to be exploited, though it still urged organizations using SharePoint to upgrade to a fixed version as soon as possible.

CISA’s KEV catalog is regularly updated based on verified reports, but it does not offer details about the exploitation of the added flaws nor does it usually point to published third-party reports.

Microsoft has yet to update the security advisory to say that the flaw is under active attack.

By adding the flaw to the KEV catalog, CISA has ordered US federal civilian agencies to address it by March 21, 2026. Private sector and other public sector organizations that use SharePoint should do it as well (if they haven’t already).

Since SharePoint servers often contain valuable corporated data and can also be used as a gateway to the entire corporate environment, SharePoint vulnerabilities are regularly leveraged by various attackers.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/03/19/sharepoint-vulnerability-cve-2026-20963-exploited/