Critical SharePoint RCE Requires Immediate Patch

CERT-EU and Microsoft confirmed an unauthenticated remote-code-execution vulnerability in SharePoint (CVE-2026-20963). The bug is CVSS 9.8, was added to CISA's KEV list, and is fixed along with three other SharePoint RCEs in Microsoft's March 2026 updates for Subscription Edition, 2019 and 2016.

Part of the PlainSec briefing for 2026-03-26

Sources