patch&proof.
← The dispatch

collaboration / Source brief

A SharePoint flaw moved into the known-exploited queue

CERT-EU reported that Microsoft updated its January advisory for CVE-2026-20963 on 17 March, and CISA added the unauthenticated remote-code-execution flaw…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

A SharePoint flaw moved into the known-exploited queue.

What happened. CERT-EU reported that Microsoft updated its January advisory for CVE-2026-20963 on 17 March, and CISA added the unauthenticated remote-code-execution flaw to KEV on 18 March.

Impact and confidence

Active exploitation is established by the KEV listing. The advisory applies to supported on-premises SharePoint Server editions, not an undifferentiated “Microsoft cloud.”

Defensive takeaway

Prioritize internet-facing servers, apply supported updates, and assess possible compromise rather than treating patch completion as proof that no earlier access occurred.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2026-03-25
Event date
2026-03-18
Site publication
Unpublished · local review
Critical Vulnerability in SharePoint Exploited
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval