CVE-2026-20963Active Exploitation(microsoft / sharepoint_server)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 39 mentions and remains active

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-21. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 74 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 107 mentions across 20 observed days

What's happening

  • Active exploitation reported across 74 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 53 signals
  • Technical details provided in 59 signals
  • General: 13 classified signals
  • Peaked 18d ago at 39 mentions (2026-03-19); latest day: 1
  • 107 total mentions across 20 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline107 mentions / 20d
010202939Mentions · 2026-03-18: 6Mentions · 2026-03-19: 39Mentions · 2026-03-20: 20Mentions · 2026-03-21: 6Mentions · 2026-03-22: 2Mentions · 2026-03-23: 2Mentions · 2026-03-24: 3Mentions · 2026-03-25: 10Mentions · 2026-03-26: 5Mentions · 2026-03-28: 2Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-04-05: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-16: 2Mentions · 2026-04-27: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-05-05: 1Exploit Tool / Code · 2026-03-20: 1Active Exploitation · 2026-03-18: 2Active Exploitation · 2026-03-19: 35Active Exploitation · 2026-03-20: 13Active Exploitation · 2026-03-21: 3Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-24: 3Active Exploitation · 2026-03-25: 4Active Exploitation · 2026-03-26: 2Active Exploitation · 2026-03-28: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-16: 2Active Exploitation · 2026-05-05: 2Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-18: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 16Patch / Workaround · 2026-03-20: 11Patch / Workaround · 2026-03-21: 3Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 8Patch / Workaround · 2026-03-26: 3Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-03-18: 5Technical Details · 2026-03-19: 20Technical Details · 2026-03-20: 10Technical Details · 2026-03-21: 3Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 7Technical Details · 2026-03-26: 3Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-27: 1Technical Details · 2026-05-18: 103-1803-2003-2203-2403-2603-2904-0504-1504-2705-0605-18
Signal classification4 categories
Active Exploitation
7065.4%
Patch
1615.0%
General
1312.1%
Disclosure
87.5%
Referenced assets72 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-186
Active Exploitation2Disclosure3Patch1
2026-03-1939
Active Exploitation34Disclosure1General2Patch2
2026-03-2020
Active Exploitation12Disclosure1General4Patch3
2026-03-216
Active Exploitation3Disclosure1General2
2026-03-222
Active Exploitation1General1
2026-03-232
Active Exploitation2
2026-03-243
Active Exploitation3
2026-03-2510
Active Exploitation4Disclosure2Patch4
2026-03-265
Active Exploitation2General1Patch2
2026-03-282
Active Exploitation1General1
2026-03-291
General1
2026-03-301
Active Exploitation1
2026-04-051
General1
2026-04-141
Patch1
2026-04-151
Active Exploitation1
2026-04-162
Patch2
2026-04-271
Patch1
2026-05-052
Active Exploitation2
2026-05-061
Active Exploitation1
2026-05-181
Active Exploitation1
Full discourse20 posts
  • LuemmelSec@theluemmel
    Patch

    Whoopsi: CVE-2026-20963 is now UNAUTHENTICATED!!!! Patch ASAP. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 Updated the scanner: https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/Azure/Get-SPVersionInfo.ps1 https://t.co/LVjBatCzTy

    Post summary

    The post alerts that CVE-2026-20963 is now unauthenticated and urges immediate patching, providing a Microsoft advisory link.

    5139554739358.2K
    8.3K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    وش السالفة في ثغرة SharePoint (CVE-2026-20963)؟ الثغرة هذي تصنف من نوع (Deserialization of untrusted data)، وببساطة الهكر يقدر يرسل بيانات "ملغمة" للسيرفر، والسيرفر لما يجي يعالجها (Process) ينفذ الكود الخبيث اللي داخلها فوراً. المصيبة الكبرى إنها (Pre-authentication)، يعني الهكر ما يحتاج يكون عنده يوزر ولا باسوورد عشان يدخل ويتحكم بالسيرفر. معلومات عن الاستغلال: 💻 تنفيذ أوامر عن بُعد (Remote Code Execution): بمجرد استغلال الثغرة، الهكر يصير كأنه جالس قدام السيرفر وبكامل الصلاحيات، يقدر يحذف، يعدل، أو يسرق أي بيانات حساسة. 📡 الوصول عبر الشبكة (Network-based): الهجوم يصير من برا، ما يحتاج يكون الهكر داخل شبكتك أو عنده وصول فيزيائي، وهذا اللي يخليها خطر حقيقي على أي سيرفر SharePoint مربوط بالإنترنت. ⚠️ CISA أضافتها لقائمة (KEV) لأن فيه هجمات منظمة جالسة تصير عليها الحين. مايكروسوفت نزلت التحديث (Patch) الخاص بها في يناير ٢٠٢٦، و CISA حددت مهلة نهائية للجهات الحكومية والمنشآت الحساسة لليوم (٢٣ مارس ٢٠٢٦) عشان يقفلونها تماماً، وهذا يوضح لك قد ايش الموضوع حرج والوقت ضيق. إذا أنتم تستخدمون SharePoint في بيئتكم، لا تكتفون بس بالتحديث . ثغرات الـ Deserialization دايم تترك "أثر" خلفها. نصيحة راجعوا الـ (Logs) حق السيرفرات. ابحثوا عن أي طلبات (Web Requests) مشبوهة أو عمليات (Processes) غريبة طلعت فجأة. الهجمات بدت قبل التحذير هذا بفترة، والهدف دايم يكون "الوصول الأولي" للشبكة الداخلية.

    Post summary

    The post highlights that CVE‑2026‑20963 is actively exploited by attackers without authentication, with Microsoft having issued a patch and CISA warning for critical entities.

    28114012418.3K
    47.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    Microsoft مايرتاحون الا اذ خربو الاجازات والاعياد 🤦🏻‍♂️🤦🏻‍♂️🤦🏻‍♂️ CVE-2026-20963

    Post summary

    The text merely cites a CVE number without providing any technical, exploit, or mitigation information.

    241736252.0K
    47.2K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Disclosure

    We added Microsoft SharePoint CVE-2026-20963 (post-auth deserialization RCE) to our scanning & daily feeds. 1109 IPs found running vulnerable instances worldwide (close to 1900 FQDNs) on 2026-03-19, with 510 IPs in the US. Dashboard World Map: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-20963%2B&data_set=count&scale=log&auto_update=on https://t.co/WlYmfaxBSi

    Post summary

    This post announces the addition of CVE‑2026‑20963 to scanning feeds and shares a dashboard indicating the number of vulnerable SharePoint instances worldwide, but offers no PoC, exploit, patch, or active exploitation information.

    220047296.3K
    21.7K followersView on X
  • Abdullah 🇸🇦@A_cyb3r
    General

    مشاركة ثعلوب 🦊 اليوم عن الثغرة CVE-2026-20963 Microsoft SharePoint (2016, 2019, Subscription Edition) طبعاً هو مساعد ذكي مبني على openclaw + deepseek ، جعلته المسؤول عن المشاركات في القروب ويومياً ينشر مشاركة تقنية ، ميزته انه يسمع الكلام .. https://t.co/AwQl1ngPCc

    Post summary

    The tweet references CVE‑2026‑20963 without providing any technical details, exploitation information, or mitigation guidance.

    12027174.7K
    9.8K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Two updates from the Defused honeypot lab 1️⃣ New FortiClient EMS decoy deployed CVE-2026-21643 (pre-auth SQLi, CVSS 9.1) - Bishop Fox just dropped a full exploitation writeup for FortiClient EMS 7.4.4. No public exploitation observed yet but with a detailed writeup now out, it's a matter of time. We've added a FortiClient EMS honeypot stream to catch early exploitation attempts 🍯 2️⃣ SharePoint CVE-2026-20963 added to CISA KEV Microsoft SharePoint deserialization flaw - actively exploited in the wild. RCE via crafted network requests, no auth required. Track exploitation attempts against our SharePoint decoys on the platform. 👉 http://console.defusedcyber.com/signup

    Post summary

    Defused honeypot lab reports that Microsoft SharePoint CVE‑2026‑20963 is actively exploited in the wild, while a PoC writeup for FortiClient EMS CVE‑2026‑21643 has been released, though no exploitation has yet been observed for that vulnerability.

    1922664.1K
    6.2K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft SharePoint deserialization of untrusted data vulnerability CVE-2026-20963 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/ACTOITJV9V

    Post summary

    The tweet announces CVE‑2026‑20963—a deserialization flaw in Microsoft SharePoint—was added to the DHS KEV catalog, indicating it is being actively exploited in the wild.

    31102645.8K
    293.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️CISA has added 2 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2025-66376: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability. CVSS: 7.1 CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. CVSS: 8.8

    Post summary

    The post announces that CISA has added two vulnerabilities to the KEV Catalog, providing brief technical details and CVSS scores, but offers no PoC, exploit code, patch, or active exploitation claim.

    1501764.6K
    174.6K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @theluemmel @theluemmel "Whoopsi" is right. SharePoint deserialization RCE at CVSS 9.8 was bad enough when it needed auth. Now CVE-2026-20963 is unauthenticated - the attack surface just went from "stolen creds" to "anyone with a URL." Patch ASAP. https://vulntracker.io

    Post summary

    The tweet announces that CVE‑2026‑20963 is an unauthenticated SharePoint deserialization RCE with a CVSS score of 9.8 and urges immediate patching.

    0101072.6K
    448 followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CISA adds actively exploited Microsoft SharePoint RCE (CVE-2026-20963) and Zimbra XSS (CVE-2025-66376) to its KEV catalog. Update your systems immediately. #CISA #KEVCatalog #SharePoint #Zimbra #CyberSecurity #InfoSec #CVE #RCE #Vulnerability #PatchAlert https://securityonline.info/exploited-in-wild-cisa-kev-catalog-sharepoint-zimbra-vulnerabilities/ https://t.co/naJO9wRcWF

    Post summary

    CISA has identified Microsoft SharePoint RCE (CVE‑2026‑20963) and Zimbra XSS (CVE‑2025‑66376) as actively exploited, urging immediate system updates.

    03162821
    10.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/18追加) 🛡️No.1546 CVE-2026-20963 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability ===================================== ✅概要 ・深刻度:重要⚠️ 8.8 (CVSS Base) / Microsoft ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft SharePoint において、信頼されていないデータのデシリアライズ処理に不備があり、攻撃者が細工したデータを処理させることで任意コード実行につながる可能性がある脆弱性。 認証済ユーザー権限で悪用可能であり、SharePoint サーバ上でコード実行が成立する恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:中 ✅攻撃前提条件 ・攻撃者が SharePoint 環境に対して認証済みアクセスを持つこと(PR:L) ・脆弱な SharePoint バージョンが稼働していること ・細工されたデータをサーバ側で処理させること ✅悪用時影響 ・SharePoint サーバ上での任意コード実行 ・機密情報の窃取(ドキュメント・認証情報など) ・権限昇格および横展開 ・組織内システム全体への侵害拡大 ✅悪用事例等に関する公開情報 ・PoC/Exploit:確認できず ・ITW:確認できず(2026/03時点) ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20963 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-adds-one-known-exploited-vulnerability-catalog-0 #vulnetability

    Post summary

    CISA reports that CVE-2026-20963, a deserialization flaw in Microsoft SharePoint, is actively exploited in the wild. No PoC, exploit code, or patch information is provided in the text.

    020813.9K
    42.8K followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca
    General

    #CyberAlert | Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-20963 https://www.cyber.gc.ca/en/alerts-advisories/al26-005-critical-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-20963 https://t.co/l3GFbdTmVn

    Post summary

    The tweet posts a link to a government alert about CVE‑2026‑20963 affecting Microsoft SharePoint Server, but it provides no further technical detail, PoC, or exploitation information.

    10032795
    33.9K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) https://www.helpnetsecurity.com/2026/03/19/sharepoint-vulnerability-cve-2026-20963-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA has warned that Microsoft SharePoint CVE-2026-20963 is being actively exploited in the wild.

    02040516
    193.8K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    Vulnerable IPs (tagged 'cve-2026-20963') shared daily in our Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ CVE-2026-20963 is known exploited in the wild and on @CISACyber KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20963 Check for compromise. Microsoft Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963

    Post summary

    The post highlights that CVE-2026-20963 is actively exploited in the wild, shares daily vulnerable IP lists, cites official advisories, and urges users to check for compromise.

    11030835
    21.7K followersView on X
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    🔍 Attention, security professionals! New critical CVEs require immediate action: CVE-2026-20963 (SharePoint) – RCE via deserialization CVE-2025-48827 (vBulletin) – CVSS 10.0, actively exploited CVE-2025-70401/70400 (UniFi) – Path traversal and RCE with network access CVE-2023-43010 (Apple) – Memory corruption in Safari and iOS ✅ Stay up to date. 🛠️ Patches are now available. 🚨 Real threats, urgent response. #Cybersecurity #CVE #InfoSec #CISAKEV #PatchNow

    Post summary

    Multiple critical CVEs are announced, including one actively exploited, and vendor‑issued patches are available, prompting immediate action.

    01030122
    3.2K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 استغلال نشط لثغرة أمنية في عشرات خوادم SharePoint الهولندية كشف تحليل مؤسسة Shadowserver عن استغلال نشط لثغرة أمنية (CVE-2026-20963) تستهدف عشرات خوادم Microsoft SharePoint ذات عناوين IP هولندية. يشير هذا الاستغلال الجاري إلى مخاطر عالية لاختراق الأنظمة وسرقة البيانات. يجب على المؤسسات التي تدير هذه الخوادم اتخاذ إجراءات فورية للتخفيف من التهديد. يُنصح بشدة بتطبيق التحديثات الأمنية العاجلة لمعالجة الثغرة وإجراء مسح شامل للكشف عن أي مؤشرات اختراق محتملة. 🔗 للمزيد: https://www.security.nl/posting/929513/%27Tientallen+Nederlandse+SharePoint-servers+bevatten+actief+misbruikt+lek%27?channel=rss

    Post summary

    The post reports active exploitation of CVE-2026-20963 on Dutch SharePoint servers, urging immediate patching, but provides no PoC, exploit code, or detailed technical description.

    00030501
    80 followersView on X
  • Tech Fusionist@techyoutbe
    Active Exploitation

    4️⃣ CISA added a Microsoft SharePoint flaw to its Known Exploited Vulnerabilities list. CVE-2026-20963 is now being actively exploited in the wild. 👉 Why it matters: if your org runs SharePoint, this just became an urgent patching priority.

    Post summary

    The tweet highlights that Microsoft SharePoint CVE-2026-20963 is actively exploited, has been added to CISA’s Known Exploited Vulnerabilities list, and urgent patching is required.

    10011723
    55.1K followersView on X
  • Pentest_Testing_Corp@pentesttesting
    General

    CVE-2026-20963 put SharePoint back in the spotlight. If you run self-managed SharePoint, the first 48 hours matter most. We break down triage, evidence preservation before patching.. https://www.pentesttesting.com/cve-2026-20963-sharepoint-first-48-hours #CyberSecurity #SharePoint #InfoSec #IncidentResponse #DFIR #ThreatIntel

    Post summary

    The tweet references CVE-2026-20963 and highlights triage timing for self‑managed SharePoint, but does not provide any PoC, exploit details, patch, or technical information.

    00020117
    8 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-27522 2 - CVE-2026-3055 3 - CVE-2025-58718 4 - CVE-2026-20963 5 - CVE-2026-21858 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without any additional technical detail, proof‑of‑concept, exploit code, patch information, or claim of active exploitation.

    00020354
    1.7K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/03/18:Microsoft SharePoint の脆弱性 CVE-2026-20963 を登録 https://iototsecnews.jp/2026/03/19/cisa-warns-of-microsoft-sharepoint-vulnerability-exploited-in-attacks/ この脆弱性 CVE-2026-20963 は、 Microsoft SharePoint が外部から届いたデータを処理する際の不備に起因します。本来であれば、ネットワーク上を流れるデータは、安全性を厳密に確認してからシステム内で使える形に戻す必要がありますが、そのためのデシリアライズ処理に問題が発生しています。この隙を突かれると、攻撃者が送り込んだ不正な命令が、あたかも正規の処理であるかのようにサーバ上で実行されてしまいます。認証情報を必要とせずに遠隔から操作を許してしまうため、厳重な対応が必要です。ご利用のチームは、ご注意ください。 #CISA #CVE202620963 #Exploit #Government #KEV #Microsoft #SharePoint #Vulnerability

    Post summary

    The post reports that Microsoft SharePoint CVE-2026-20963 is being actively exploited via a deserialization flaw that permits unauthenticated remote code execution, with no patch or mitigation detail provided.

    01001203
    481 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more