cbcvebase.
CVE-2026-20963
published 2026-01-13

CVE-2026-20963: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-03-21
Exploited in the wild
EPSS
29.43%
98.0th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5535.100116.0.5535.1001
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2008316.0.10417.20083
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.19127.2044216.0.19127.20442
microsoftsharepoint_server< 16.0.19127.2044216.0.19127.20442
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition

Detection & IOCsextracted from sources · hover to see the quote

  • Target attack surface: unauthenticated, network-based deserialization of untrusted data against SharePoint Server — no credentials required, low complexity
  • Affected products to prioritize for detection/patching: SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition (also unpatched: 2007, 2010, 2013)
  • Vulnerability is confirmed actively exploited in the wild per CISA KEV; EPSS exploitation probability at 90.7th percentile — prioritize detection on internet-facing SharePoint servers
  • CISA KEV confirmed active exploitation; no ransomware linkage found yet but threat actor activity is ongoing — monitor SharePoint servers for anomalous process spawning or code execution
  • ·Microsoft's own advisory still marks exploitation status as 'Exploited: No' despite CISA KEV listing — defenders should trust CISA KEV over MSRC advisory for patching urgency
  • ·End-of-support SharePoint versions (2007, 2010, 2013) are vulnerable but will NOT receive patches — environments running these must upgrade or isolate
  • ·No further technical details (specific endpoint, payload format, PoC) have been publicly disclosed by CISA or Microsoft at time of reporting

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.