RCE Critica in SharePoint Richiede Patch Immediata
La falla ha CVSS 9.8 e figura nel catalogo CISA Known Exploited Vulnerabilities. Gli aggiornamenti di marzo risolvono CVE-2026-20963 e altri tre RCE per Subscription Edition, 2019 e 2016.
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 30% (98º percentile).
Data di correzione federale CISA 21 mar · data superata
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 2% (82º percentile). Patch Microsoft: 5002850.
CVSS 8.8 HIGH: improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. EPSS 1% (69º percentile). Patch Microsoft: 5002850.