CVE-2026-20963
Known exploited · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 33% (98th percentile).
CISA federal remediation date Mar 21
Vulnerabilities & Exploits · Web App Attack
Microsoft SharePoint Server 2016, 2019, and Subscription Edition are being exploited in the wild via CVE-2026-20963. Microsoft released a January 2026 security patch and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline.
3 sources · Mar 19
Known exploited · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 33% (98th percentile).
CISA federal remediation date Mar 21
Help Net Security
CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) - Help Net Security
CVE-2026-20963, a remote code execution (RCE) SharePoint vulnerability Microsoft fixed in January 2026, is being exploited by attackers.
originalSecurityWeek
CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability
The SharePoint remote code execution vulnerability CVE-2026-20963, which Microsoft patched in January, has been exploited in the wild.
originalBleepingComputer
Critical Microsoft SharePoint flaw now exploited in attacks
A critical Microsoft SharePoint vulnerability patched in January is now being exploited in attacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned.
originalPart of the PlainSec briefing for 2026-03-21
Every edition of this story: Critical SharePoint Flaw Being Actively Exploited