CVE-2026-20963
📛 CVE Title
Microsoft SharePoint Remote Code Execution Vulnerability
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- CRITICAL
- CVSS score
- 9.8 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 9.8 / 10 CRITICAL source: CNA overview
- MSRC score
- 9.8 / 10 CRITICAL MS rating: Important · Remote Code Execution
- CWE(s)
-
CWE-502 - Reserved
- 2025-12-04
- Published
- 2026-01-13 08:00 UTC
- Last updated
- 2026-03-17 07:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/20xxx/CVE-2026-20963.json
- Linked Threat
- CVE-2026-20963 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
- Vendor / project
- Microsoft
- Product
- SharePoint
- Date added to KEV
- 2026-03-18
- Remediation due
- 2026-03-21
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Unknown
- CISA notes
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20963
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-01-13 18:16:24 UTC
- NVD last modified
- 2026-04-01 16:01:22 UTC
- NVD CVSS v3.1
- 9.8 / 10 CRITICAL source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0562 (probability of exploitation in next 30 days)
- EPSS percentile
- 90.44% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 04:10 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-2114 - Assigner
- microsoft
- Published
- Jan 13, 2026, 5:56:49 PM
- Updated
- Apr 2, 2026, 3:55:34 AM
- EUVD base score (CVSS 3.1)
-
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 5.2900
- Vendors
- Microsoft
- Products
-
Microsoft SharePoint Server 2019 (16.0.0 <16.0.10417.20083)Microsoft SharePoint Server Subscription Edition (16.0.0 <16.0.19127.20442)Microsoft SharePoint Enterprise Server 2016 (16.0.0 <16.0.5535.1001)
- Aliases
-
GHSA-5vr8-9cf6-r7px
ENISA description: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-31 03:00 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Remote Code Execution
- MS CVSS base score
- 9.8 / 10 (temporal 8.5)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
- Release
- 2026-Jan
Microsoft remediations / KB articles (6)
- 5002828 — Vendor Fix / Security Update (fixed build 16.0.5535.1001)
- https://support.microsoft.com/help/5002828 — None Available / 5002828
- 5002825 — Vendor Fix / Security Update (fixed build 16.0.10417.20083)
- https://support.microsoft.com/help/5002825 — None Available / 5002825
- 5002822 — Vendor Fix / Security Update (fixed build 16.0.19127.20442)
- https://support.microsoft.com/help/5002822 — None Available / 5002822
Microsoft FAQ (1)
How could an attacker exploit this vulnerability?
In a network-based attack, an unauthenticated attacker could write arbitrary code to inject and execute code remotely on the SharePoint Server.
Affected products (3)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 |
16.0.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft SharePoint Server 2019 |
16.0.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft SharePoint Server Subscription Edition |
16.0.0 (affected)
|
x64-based Systems |
Affected products — CPE 2.3 (3) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Microsoft SharePoint Remote Code Execution Vulnerability vendor-advisorypatch
Web references (11)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5002822 msrc
- 5002828 msrc
- 5002825 msrc
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 rapid7:msrc.microsoft.com
- https://support.microsoft.com/help/5002822 rapid7:support.microsoft.com
- http://cwe.mitre.org/data/definitions/502.html rapid7:cwe.mitre.org
- https://support.microsoft.com/help/5002828 rapid7:support.microsoft.com
- https://www.cve.org/CVERecord?id=CVE-2026-20963 rapid7:www.cve.org
- https://support.microsoft.com/help/5002825 rapid7:support.microsoft.com
- https://attackerkb.com/topics/CVE-2026-20963 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2114 rapid7:euvd.enisa.europa.eu
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963 secure@microsoft.com Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20963 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cwe |
CWE-502
|
no local data | 2026-05-14 02:58 UTC |
| cve |
CVE-2026-20963
|
no local data | 2026-05-14 02:58 UTC |
Remediations (1)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-21 Known ransomware campaign use: Unknown
2026-05-14 01:13 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-20963.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-20963",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-08T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-03-18",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20963"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-02T03:55:34.121Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20963"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft SharePoint Enterprise Server 2016",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.5535.1001",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft SharePoint Server 2019",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.10417.20083",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft SharePoint Server Subscription Edition",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.19127.20442",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*",
"versionEndExcluding": "16.0.5535.1001",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.0.10417.20083",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
"versionEndExcluding": "16.0.19127.20442",
"versionStartIncluding": "16.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-01-13T16:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502: Deserialization of Untrusted Data",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-01T13:49:28.600Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft SharePoint Remote Code Execution Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963"
}
],
"title": "Microsoft SharePoint Remote Code Execution Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2026-20963",
"datePublished": "2026-01-13T17:56:49.798Z",
"dateReserved": "2025-12-04T20:04:16.341Z",
"dateUpdated": "2026-04-02T03:55:34.121Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}