Vulnerabilità ed exploit · Attacco ad app web

RCE Non Autenticata in SharePoint Aggiunta al KEV

La falla è valutata CVSS 9.8 ed è stata aggiunta al catalogo Known Exploited Vulnerabilities di CISA.

1 fonte · 25 mar

CVE-2026-20963

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 30% (98º percentile).

Data di correzione federale CISA 21 mar · data superata

CVE-2026-26114

NVD KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 2% (82º percentile). Patch Microsoft: 5002850.

Patch disponibile KB5002850 Scarica →

CVE-2026-26106

NVD KEV

CVSS 8.8 HIGH: improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. EPSS 1% (69º percentile). Patch Microsoft: 5002850.

Patch disponibile KB5002850 Scarica →

CVE-2026-26113

NVD KEV

CVSS 8.4 HIGH: untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. Patch Microsoft: 5002850.

Patch disponibile KB5002850 Scarica →

Cronologia

Fonti

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: RCE Non Autenticata in SharePoint Aggiunta al KEV

Altro da oggi