CVE-2026-20963, a critical SharePoint remote-code-execution flaw patched by Microsoft in January, is being exploited in the wild. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline.
Part of the PlainSec briefing for 2026-03-25