Vulnerabilità ed exploit · Attacco ad app web

Falla Critica in SharePoint Sfruttata Attivamente

Una vulnerabilità RCE identificata come CVE-2026-20963 interessa Microsoft SharePoint ed è stata osservata in attacco. Microsoft ha rilasciato patch a gennaio 2026 per SharePoint Server 2016, 2019 e Subscription Edition.

3 fonti · 19 mar

CVE-2026-20963

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 30% (98º percentile).

Data di correzione federale CISA 21 mar

Cronologia

Fonti

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-03-23

Every edition of this story: Falla Critica in SharePoint Sfruttata Attivamente

Altro da oggi