logo

Unknown attackers exploit yet another critical SharePoint bug

ID: 717f77b7-b0fc-5570-9df0-a8fccf7c86ad

STIX ID: report--717f77b7-b0fc-5570-9df0-a8fccf7c86ad

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-03-19

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

US authorities warn that CVE-2026-20963, a critical unauthenticated deserialization remote code execution flaw in Microsoft SharePoint, is being abused in the wild and was added to CISA's KEV with an emergency patching window for federal agencies; Microsoft patched the issue in January and the report contextualizes the risk by recalling prior mass SharePoint exploitation linked to China-based threat groups and ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.