Vulnerabilità ed exploit · Attacco ad app web

RCE Critica in SharePoint Richiede Patch Immediata

La falla ha CVSS 9.8 e figura nel catalogo CISA Known Exploited Vulnerabilities. Gli aggiornamenti di marzo risolvono CVE-2026-20963 e altri tre RCE per Subscription Edition, 2019 e 2016.

1 fonte · 25 mar

CVE-2026-20963

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 30% (98º percentile).

Data di correzione federale CISA 21 mar · data superata

CVE-2026-26114

NVD KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 2% (82º percentile). Patch Microsoft: 5002850.

Patch disponibile KB5002850 Scarica →

CVE-2026-26106

NVD KEV

CVSS 8.8 HIGH: improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. EPSS 1% (69º percentile). Patch Microsoft: 5002850.

Patch disponibile KB5002850 Scarica →

CVE-2026-26113

NVD KEV

CVSS 8.4 HIGH: untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. Patch Microsoft: 5002850.

Patch disponibile KB5002850 Scarica →

Cronologia

Fonti

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: RCE Critica in SharePoint Richiede Patch Immediata

Altro da oggi