Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights SharePoint Security Vulnerability Exploitation

CISA Highlights SharePoint Security Vulnerability Exploitation

Posted on March 19, 2026 By CWS

A critical security flaw in Microsoft SharePoint has come under active exploitation, as highlighted by the Cybersecurity and Infrastructure Security Agency (CISA). This vulnerability, identified as CVE-2026-20963, was initially revealed in Microsoft’s January 2026 Patch Tuesday updates.

Urgent Call for Federal Agency Action

On March 18, CISA incorporated CVE-2026-20963 into its Known Exploited Vulnerabilities (KEV) catalog, compelling federal agencies to implement fixes by March 21. The flaw is a significant remote code execution vulnerability with a CVSS score of 9.8, caused by deserialization of untrusted data.

Microsoft’s description of the flaw includes its impact on SharePoint Server 2016, 2019, and Subscription Edition. The vulnerability was reported by an anonymous researcher and poses a risk where an unauthenticated user could insert and execute arbitrary code on affected servers.

Microsoft’s Response and Advisory

Despite updating their advisory on March 17, Microsoft has not confirmed any active exploitation of this vulnerability. The company’s exploitability assessment suggests that exploitation is ‘less likely’. However, CISA’s warning indicates a potential risk that necessitates immediate attention.

There is currently limited public information regarding incidents that have leveraged this vulnerability. SecurityWeek has contacted Microsoft for further insights and awaits a response.

Ongoing Security Challenges

CISA’s KEV catalog now lists nine vulnerabilities related to SharePoint, including three from 2025 associated with the ToolShell attacks. This highlights the continuing challenges in securing enterprise systems against evolving threats.

For those managing SharePoint environments, this serves as a critical reminder to stay vigilant and ensure all security patches are applied promptly to mitigate potential risks.

Related issues include a Cisco firewall vulnerability exploited in Interlock ransomware attacks and phishing campaigns abusing SharePoint to target the energy sector.

Security Week News Tags:CISA, CVE-2026-20963, Cybersecurity, KEV catalog, Microsoft, network attack, remote code execution, security update, SharePoint, Vulnerability

Post navigation

Previous Post: DarkSword iOS Kit Exploits Multiple Flaws for Device Control
Next Post: Iran-Linked Botnet Unveiled Through Open Directory Leak

Related Posts

Microsoft Defender’s Vulnerability Exploited in Zero-Day Attack Microsoft Defender’s Vulnerability Exploited in Zero-Day Attack Security Week News
Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak Security Week News
Palo Alto Networks Vulnerability Under Active Exploitation Palo Alto Networks Vulnerability Under Active Exploitation Security Week News
US Seeks Forfeiture of .74M in Cryptocurrency Tied to North Korean IT Workers US Seeks Forfeiture of $7.74M in Cryptocurrency Tied to North Korean IT Workers Security Week News
Fortinet, Ivanti Patch High-Severity Vulnerabilities Fortinet, Ivanti Patch High-Severity Vulnerabilities Security Week News
Cloaked Secures 5M to Boost Privacy Tools and Enterprise Expansion Cloaked Secures $375M to Boost Privacy Tools and Enterprise Expansion Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Accenture Enhances OT Cybersecurity with Strategic Acquisitions
  • Identify Hidden Risks from Orphaned AI Tools
  • Strengthening Cybersecurity in 2026: Modern Data Protection
  • Network Security Challenges: No Exploits Needed
  • Cyberattack Uses Windows Scripts to Deploy Xctdoor Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Accenture Enhances OT Cybersecurity with Strategic Acquisitions
  • Identify Hidden Risks from Orphaned AI Tools
  • Strengthening Cybersecurity in 2026: Modern Data Protection
  • Network Security Challenges: No Exploits Needed
  • Cyberattack Uses Windows Scripts to Deploy Xctdoor Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark