CERT-EU and Microsoft confirmed an unauthenticated remote-code-execution vulnerability in SharePoint (CVE-2026-20963). The bug is CVSS 9.8, was added to CISA's KEV list, and is fixed along with three other SharePoint RCEs in Microsoft's March 2026 updates for Subscription Edition, 2019 and 2016.
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 33% (98th percentile).
CISA federal remediation date Mar 21 · date passed
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 3% (86th percentile). Microsoft patch: 5002850.
CVSS 8.8 HIGH: improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. EPSS 1% (69th percentile). Microsoft patch: 5002850.