CVE-2026-20963
published 2026-01-13CVE-2026-20963: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-03-21
Exploited in the wild
EPSS
29.43%
98.0th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5535.1001 | 16.0.5535.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20083 | 16.0.10417.20083 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19127.20442 | 16.0.19127.20442 |
| microsoft | sharepoint_server | < 16.0.19127.20442 | 16.0.19127.20442 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target attack surface: unauthenticated, network-based deserialization of untrusted data against SharePoint Server — no credentials required, low complexity ↗
- →Affected products to prioritize for detection/patching: SharePoint Enterprise Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition (also unpatched: 2007, 2010, 2013) ↗
- →Vulnerability is confirmed actively exploited in the wild per CISA KEV; EPSS exploitation probability at 90.7th percentile — prioritize detection on internet-facing SharePoint servers ↗
- →CISA KEV confirmed active exploitation; no ransomware linkage found yet but threat actor activity is ongoing — monitor SharePoint servers for anomalous process spawning or code execution ↗
- ·Microsoft's own advisory still marks exploitation status as 'Exploited: No' despite CISA KEV listing — defenders should trust CISA KEV over MSRC advisory for patching urgency ↗
- ·End-of-support SharePoint versions (2007, 2010, 2013) are vulnerable but will NOT receive patches — environments running these must upgrade or isolate ↗
- ·No further technical details (specific endpoint, payload format, PoC) have been publicly disclosed by CISA or Microsoft at time of reporting ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
cisa·2026-03-18·CVSS 9.8
CVE-2026-20963 [CRITICAL] CWE-502 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Vulnerability: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affected: Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20963
Remediation Due Date: 2026-03-21
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2026-01-13·CVSS 9.8
CVE-2026-20963 [CRITICAL] CWE-502 Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
FAQ: How could an attacker exploit this vulnerability?
In a network-based attack, an unauthenticated attacker could write arbitrary code to inject and execute code remotely on the SharePoint Server.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=108518
Reference: https://support.microsoft.com/help/5002828
Reference: https://www.mi
GHSA
GHSA-5vr8-9cf6-r7px: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2026-01-13
CVE-2026-20963 [HIGH] CWE-502 GHSA-5vr8-9cf6-r7px: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
VulnCheck
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-20963 [CRITICAL] CWE-502 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Affected: Microsoft SharePoint
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2026-03-21
No detection rules found.
No public exploits indexed.
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Bleepingcomputer
Critical Microsoft SharePoint flaw now exploited in attacks
blogs_bleepingcomputer·2026-03-19·CVSS 9.8
CVE-2026-20963 [CRITICAL] Critical Microsoft SharePoint flaw now exploited in attacks
## Critical Microsoft SharePoint flaw now exploited in attacks
## Sergiu Gatlan
A critical Microsoft SharePoint vulnerability patched in January is now being exploited in attacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned.
Tracked as CVE-2026-20963 , this security flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
SharePoint Server 2007, SharePoint Server 2010, and SharePoint Server 2013 are also vulnerable to attacks but are end-of-support and no longer receive security updates. Admins are advised to upgrade end-of-support SharePoint Server versions to a supported version to block attacks.
Successful exploitation enables threat actors without privileges to achieve remote code execution on unpatc
Qualys
Microsoft and Adobe Patch Tuesday, January 2026 Security Update Review
blogs_qualys·2026-01-13
Microsoft and Adobe Patch Tuesday, January 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forJanuary2026
Adobe Patches for January 2026
Zero-day Vulnerabilities Patched inJanuaryPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inJanuaryPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response with TruRisk Eliminate
EVALUATE Vendor-Suggested Mitigation withPolicy Audit(PA)
Qualys Monthly Webinar Series
Starting the year on a security-first note, Microsoft’s January 2026 Patch Tuesday resolves several vulnerabilities that could impact enterprise environments. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for January 2026
This month’s rel
Bleepingcomputer
Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws
blogs_bleepingcomputer·2026-01-13·CVSS 5.5
[MEDIUM] Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws
## Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws
## Lawrence Abrams
57 Elevation of Privilege vulnerabilities
3 Security Feature Bypass vulnerabilities
22 Remote Code Execution vulnerabilities
22 Information Disclosure vulnerabilities
2 Denial of Service vulnerabilities
5 Spoofing vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include Microsoft Edge (1 flaw) and Mariner vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5074109 & KB5073455 cumulative updates and Windows 10 KB5073724 extended security update .
## 3 zero-days, one ex
Qualys
Microsoft and Adobe Patch Tuesday, January 2026 Security Update Review | Qualys
blogs_qualys·2026-01-13
Microsoft and Adobe Patch Tuesday, January 2026 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday forJanuary2026
- Adobe Patches for January 2026
- Zero-day Vulnerabilities Patched inJanuaryPatch Tuesday Edition
- Critical Severity Vulnerabilities Patched inJanuaryPatch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response with TruRisk Eliminate
- EVALUATE Vendor-Suggested Mitigation withPolicy Audit(PA)
- Qualys Monthly Webinar Series
Starting the year on a security-first note, Microsoft’s January 2026 Patch Tuesday resolves several vulnerabilities that could impact enterprise environments. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for January 2026
Thi
Wiz
CVE-2026-20963 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-20963 [CRITICAL] CVE-2026-20963 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20963 :
vulnerability analysis and mitigation
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Source : NVD
## 9.8
Score
Published January 13, 2026
Severity CRITICAL
CNA Score 9.8
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 90.7
Exploitation Probability (EPSS) 6
Affected packages and libraries
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Sources
Windows Severity CRITICAL Has Fix Added at: Jan 23, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Free Vulnerability Assess
2026-01-13
Published
2026-03-18
Added to CISA KEV
Exploited in the wild