A SharePoint flaw moved into the known-exploited queue.
What happened. CERT-EU reported that Microsoft updated its January advisory for CVE-2026-20963 on 17 March, and CISA added the unauthenticated remote-code-execution flaw to KEV on 18 March.
Impact and confidence
Active exploitation is established by the KEV listing. The advisory applies to supported on-premises SharePoint Server editions, not an undifferentiated “Microsoft cloud.”
Defensive takeaway
Prioritize internet-facing servers, apply supported updates, and assess possible compromise rather than treating patch completion as proof that no earlier access occurred.