logo

SharePoint Server RCE vulnerability: Find impacted assets

ID: 02b2f47d-fb3c-520a-87bb-6064d264f868

STIX ID: report--02b2f47d-fb3c-520a-87bb-6064d264f868

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2025-07-21

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

### Executive Summary The report describes critical remote code execution vulnerabilities in Microsoft SharePoint Server (notably CVE-2026-20963 and related 2025 CVEs) that permit unauthenticated attackers to execute arbitrary code; CVSS was raised to 9.8 and CVE-2026-20963 is listed on CISA's Known Exploited Vulnerabilities. Microsoft has released patches for some versions (with guidance on versions to update) and the report provides runZero queries to identify potentially affected installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.