CVE-2026-20963 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

CVE-2026-20963 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Image via

CVE-2026-20963 — Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963

What This Means For You

  • CISA has confirmed active exploitation — immediate patching required.
  • Added to CISA KEV catalog — federal agencies must remediate by 2026-03-21.

Indicators of Compromise

IDTypeIndicator
CVE-2026-20963 Deserialization Microsoft SharePoint, deserialization of untrusted data vulnerability, allows remote code execution
CVE-2026-20963 RCE Microsoft SharePoint, remote code execution over a network
Source & Attribution
Source PlatformCISA
ChannelCISA KEV
Channel IDcisa-kev
Message ID202620963
PublishedMarch 18, 2026 at 14:00 UTC
Original Linkhttps://msrc.microsoft.com/update-guide/vulnerability/CVE...

This content was curated and summarized by Shimi's Cyber World for informational purposes. It is not copied or republished in full. All intellectual property rights remain with the original author and source.

Believe this infringes your rights? Submit a takedown request.

Found this interesting? Follow us on LinkedIn to stay ahead.

Follow Shimi Cohen Follow Shimi's Cyber World
Share
LinkedIn WhatsApp Reddit