Vulnerabilities & Exploits · Web App Attack

Critical SharePoint Flaw Being Actively Exploited

Microsoft SharePoint Server 2016, 2019, and Subscription Edition are being exploited in the wild via CVE-2026-20963. Microsoft released a January 2026 security patch and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline.

3 sources · Mar 19

CVE-2026-20963

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 33% (98th percentile).

CISA federal remediation date Mar 21

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-03-20

Every edition of this story: Critical SharePoint Flaw Being Actively Exploited

More from today