CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

2026-004: Critical Vulnerability in SharePoint Exploited

criticalknown exploitedCVE-2026-20963CVE-2026-26106CVE-2026-26113CVE-2026-26114
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions.

CSIRTS triage

What
A remote code execution vulnerability can be exploited by unauthenticated attackers.
Who is affected
Deployments of Microsoft SharePoint are affected, especially internet-facing assets.
Urgency
Remediation is critical due to the high CVSS score and active exploitation.
Action
Update SharePoint servers as soon as possible.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SharePoint

Get an email when a new SharePoint advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-EU Security Advisories (EU · eu · site)
Severity
critical
Published
2026-03-25
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cert.europa.eu/publications/security-advisories/2026-004/

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-20963coverage & exploitation statusNVD · CVE.org
CVE-2026-26106coverage & exploitation statusNVD · CVE.org
CVE-2026-26113coverage & exploitation statusNVD · CVE.org
CVE-2026-26114coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CERT-EU Security Advisories