ZeroHour
CERT-EU Advisoriespublished ()ingested
Part of a story covered by 3 sources: “Critical on-prem SharePoint deserialization RCE CVE-2026-50522 (CVSS 9.8) patched; WatchTowr reports active exploitation and CISA urges hardening” — merged summary and timeline →

2026-004: Critical Vulnerability in SharePoint Exploited

AI summary · glm-5.3-flash

CVE-2026-20963 (CVSS 9.8), an unauthenticated RCE in on-prem SharePoint, was added to CISA's KEV on 18 March 2026 and is actively exploited.

CERT-EU warns about CVE-2026-20963, a CVSS 9.8 unauthenticated remote code execution flaw in SharePoint caused by deserialisation of untrusted data, affecting SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Microsoft raised the CVSS score on 17 March 2026 and the flaw entered CISA's Known Exploited Vulnerabilities catalogue on 18 March 2026. Three additional SharePoint RCE flaws (CVE-2026-26106, CVE-2026-26113, CVE-2026-26114) were fixed in the March 2026 release. CERT-EU urges immediate patching of internet-facing servers plus AMSI Full Mode, EDR deployment, ASP.NET machine key rotation, and compromise assessments.

  • CVE-2026-20963 (CVSS 9.8): unauthenticated RCE via deserialisation of untrusted data
  • Added to CISA KEV on 18 March 2026, indicating confirmed exploitation
  • Affects SharePoint Subscription Edition, Server 2019, and Enterprise Server 2016
  • Three further RCEs (CVE-2026-26106/26113/26114) patched in March 2026
  • Mitigations: AMSI in Full Mode, EDR, rotate ASP.NET machine keys

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20963
Deserialization RCE in Microsoft SharePoint Exploited in the Wild

CVE-2026-20963 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint that allows an unauthorized attacker to execute code remotely over the network. The flaw is triggered when SharePoint processes maliciously crafted serialized data without validating it, enabling an attacker to run arbitrary code in the context of the SharePoint service. Successful exploitation gives the attacker code execution on the affected SharePoint server, a foothold that typically supports further lateral movement and data access within the environment. Organizations running affected SharePoint deployments are in scope, though affected version ranges have not yet been published in the available data. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-18, confirming active exploitation, and its EPSS of 31.6% (98th percentile) indicates a high near-term probability of exploitation; no public proof-of-concept is known and CVSS scoring is not yet available.

Do: Inventory all SharePoint deployments, prioritize any internet-facing SharePoint Server instances, and apply Microsoft's security updates or vendor-specified mitigations as soon as they are available; federal agencies must follow BOD 22-01 (including cloud services) with its standard remediation timeline, and others should treat KEV inclusion as a patch-now signal despite the absence of a public PoC. Until patched, restrict network exposure of SharePoint and review server logs for signs of untrusted serialized data being processed leading to unexpected code execution.

9.833% KEV
  • Microsoft SharePoint
massOrder of millions of users across plausibly hundreds of thousands of SharePoint deployments (SharePoint Online and on-prem SharePoint Server)
CVE-2026-26114
+1 in the same advisory: …26106
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

NVD description · AI analysis pending
8.83%
  • microsoft sharepoint server
CVE-2026-26113
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more

Indicators of compromiseAll →

TypeIndicatorContext
domainasp.netMode [7]. Deploy an EDR solution. Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe . It is
Full article294 words · extracted from cert.europa.eu · click to collapse

Release Date: 25-03-2026 07:51:39

History:

  • 25/03/2026 --- v1.0 -- Initial publication

Summary

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint [1]. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026 [2].

Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release [3,4,5].

CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions.

Technical Details

The vulnerability CVE-2026-20963, with a CVSS score of 9.8, is an unauthenticated remote code execution vulnerability in Microsoft SharePoint. The flaw is due to deserialisation of untrusted data [1].

Affected Products

The vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016.

Additional information is available in the vendor's advisories [1,3,4,5].

Recommendations

CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets.

While no additional information is available and considering the Sharepoint exploitation campaign in 2025 for which we have issued a security advisory 2025-027 [9], CERT-EU recommends IT administrators, as a precautionary measure, to apply the same remediation steps once the concerned servers are up-to-date, namely:

  • Enable the Antimalware Scan Interface (AMSI) in enable Full Mode [7].
  • Deploy an EDR solution.
  • Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe.

It is also advised to conduct a compromise assessment on internet-facing assets.

References

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963

[2] https://cybersecuritynews.com/microsoft-sharepoint-vulnerability-exploited/

[3] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26106

[4] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26113

[5] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26114

[6] https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/

[7] https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration#configure-amsi-via-user-interface

[8] https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/improved-asp-net-view-state-security-key-management

[9] https://www.cert.europa.eu/publications/security-advisories/2025-027/

Text extracted automatically; images, tables and formatting may be missing. Original: https://cert.europa.eu/publications/security-advisories/2026-004/