Vulnerabilities & Exploits · Web App Attack

Critical SharePoint RCE Requires Immediate Patch

CERT-EU and Microsoft confirmed an unauthenticated remote-code-execution vulnerability in SharePoint (CVE-2026-20963). The bug is CVSS 9.8, was added to CISA's KEV list, and is fixed along with three other SharePoint RCEs in Microsoft's March 2026 updates for Subscription Edition, 2019 and 2016.

1 source · Mar 25

CVE-2026-20963

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 33% (98th percentile).

CISA federal remediation date Mar 21 · date passed

CVE-2026-26114

NVD KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 3% (86th percentile). Microsoft patch: 5002850.

Patch available KB5002850 Download →

CVE-2026-26106

NVD KEV

CVSS 8.8 HIGH: improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. EPSS 1% (69th percentile). Microsoft patch: 5002850.

Patch available KB5002850 Download →

CVE-2026-26113

NVD KEV

CVSS 8.4 HIGH: untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. Microsoft patch: 5002850.

Patch available KB5002850 Download →

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: Critical SharePoint RCE Requires Immediate Patch

More from today