LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 18, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20963 to its Known Exploited Vulnerabilities catalog on Mar 18, 2026, with a federal patch deadline of Mar 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

This vulnerability affects Microsoft SharePoint and stems from deserialization of untrusted data. An unauthorized attacker can exploit it to execute code over a network. The issue matters because SharePoint often holds internal documents and connects to broader Microsoft environments, giving an attacker a path to run arbitrary commands if the flaw is reached.

How it works

The weakness is categorized as CWE-502, deserialization of untrusted data. In this class of flaw, an application accepts serialized data from an untrusted source and reconstructs objects without sufficient validation. An attacker supplies crafted input that, when deserialized, causes the application to execute attacker-controlled code. The CISA summary states the vulnerability allows remote code execution over a network; exact input vectors and required conditions must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft SharePoint is commonly deployed as an on-premises server or accessed through Microsoft cloud services. Inventory instances by querying Microsoft 365 admin centers, running SharePoint PowerShell cmdlets to list farm servers, or reviewing configuration management databases. Check installed builds and any custom code that processes serialized input. Review network logs for unexpected inbound requests to SharePoint endpoints and monitor process creation events on SharePoint servers for anomalies following deserialization operations. Specific affected versions and configurations must be confirmed against the vendor advisory.

How to remediate

Apply mitigations per vendor instructions as the primary step. Where the product is delivered as a cloud service, follow applicable BOD 22-01 guidance. If mitigations cannot be applied, discontinue use of the affected deployment. Confirm the exact update or configuration change required by reviewing the vendor advisory directly.

If you can't patch immediately

Until a fix can be applied, restrict network access to SharePoint servers to only trusted sources. Consider virtual patching through web application firewall rules that block or sanitize serialized payloads targeting known SharePoint endpoints. Disable any non-essential features that accept untrusted serialized data. Increase monitoring of authentication and process execution logs on SharePoint hosts. Follow applicable BOD 22-01 guidance for cloud services or discontinue use if compensating controls are insufficient.

If your data may have been exposed

Actively exploited vulnerabilities of this type can result in data exposure or system compromise. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents involving their domains.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-502
Added to CISA KEVMar 18, 2026
Federal patch deadlineMar 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities