CyberzSOC

Publication detail
← Back to advisories & guidance

2026-004: Critical Vulnerability in SharePoint Exploited ↗ source

March 25, 2026 CERT-EU Advisory

Summary

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint [1]. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA’s Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026 [2]. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions. The vulnerability CVE-2026-20963, with a CVSS score of 9.8, is an unauthenticated remote code execution vulnerability in Microsoft SharePoint.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-20963 9.8 Critical Microsoft SharePoint Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-26106 8.8 High Microsoft Microsoft SharePoint Enterprise Server 2016 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26114 8.8 High Microsoft Microsoft SharePoint Enterprise Server 2016 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26113 8.4 High Microsoft Microsoft 365 Apps for Enterprise Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.