CVE-2026-20963
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 30% (98º percentile).
Data di correzione federale CISA 21 mar
Vulnerabilità ed exploit · Attacco ad app web
Una vulnerabilità RCE identificata come CVE-2026-20963 interessa Microsoft SharePoint ed è stata osservata in attacco. Microsoft ha rilasciato patch a gennaio 2026 per SharePoint Server 2016, 2019 e Subscription Edition.
3 fonti · 19 mar
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 30% (98º percentile).
Data di correzione federale CISA 21 mar
Help Net Security
CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) - Help Net Security
CVE-2026-20963, a remote code execution (RCE) SharePoint vulnerability Microsoft fixed in January 2026, is being exploited by attackers.
originaleSecurityWeek
CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability
The SharePoint remote code execution vulnerability CVE-2026-20963, which Microsoft patched in January, has been exploited in the wild.
originaleBleepingComputer
Critical Microsoft SharePoint flaw now exploited in attacks
A critical Microsoft SharePoint vulnerability patched in January is now being exploited in attacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-03-23
Every edition of this story: Falla Critica in SharePoint Sfruttata Attivamente