Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights SharePoint Security Vulnerability Exploitation

CISA Highlights SharePoint Security Vulnerability Exploitation

Posted on March 19, 2026 By CWS

A critical security flaw in Microsoft SharePoint has come under active exploitation, as highlighted by the Cybersecurity and Infrastructure Security Agency (CISA). This vulnerability, identified as CVE-2026-20963, was initially revealed in Microsoft’s January 2026 Patch Tuesday updates.

Urgent Call for Federal Agency Action

On March 18, CISA incorporated CVE-2026-20963 into its Known Exploited Vulnerabilities (KEV) catalog, compelling federal agencies to implement fixes by March 21. The flaw is a significant remote code execution vulnerability with a CVSS score of 9.8, caused by deserialization of untrusted data.

Microsoft’s description of the flaw includes its impact on SharePoint Server 2016, 2019, and Subscription Edition. The vulnerability was reported by an anonymous researcher and poses a risk where an unauthenticated user could insert and execute arbitrary code on affected servers.

Microsoft’s Response and Advisory

Despite updating their advisory on March 17, Microsoft has not confirmed any active exploitation of this vulnerability. The company’s exploitability assessment suggests that exploitation is ‘less likely’. However, CISA’s warning indicates a potential risk that necessitates immediate attention.

There is currently limited public information regarding incidents that have leveraged this vulnerability. SecurityWeek has contacted Microsoft for further insights and awaits a response.

Ongoing Security Challenges

CISA’s KEV catalog now lists nine vulnerabilities related to SharePoint, including three from 2025 associated with the ToolShell attacks. This highlights the continuing challenges in securing enterprise systems against evolving threats.

For those managing SharePoint environments, this serves as a critical reminder to stay vigilant and ensure all security patches are applied promptly to mitigate potential risks.

Related issues include a Cisco firewall vulnerability exploited in Interlock ransomware attacks and phishing campaigns abusing SharePoint to target the energy sector.

Security Week News Tags:CISA, CVE-2026-20963, Cybersecurity, KEV catalog, Microsoft, network attack, remote code execution, security update, SharePoint, Vulnerability

Post navigation

Previous Post: DarkSword iOS Kit Exploits Multiple Flaws for Device Control
Next Post: Iran-Linked Botnet Unveiled Through Open Directory Leak

Related Posts

Man Who Hacked Organizations to Advertise Security Services Pleads Guilty Man Who Hacked Organizations to Advertise Security Services Pleads Guilty Security Week News
Empirical Security Raises  Million for AI-Driven Vulnerability Management Empirical Security Raises $12 Million for AI-Driven Vulnerability Management Security Week News
Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities Security Week News
Perspective: Why Politics in the Workplace is a Cybersecurity Risk Perspective: Why Politics in the Workplace is a Cybersecurity Risk Security Week News
Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway Critical Flaw Allows Remote Hacking of AutomationDirect Industrial Gateway Security Week News
New Firefox Protections Halve the Number of Trackable Users New Firefox Protections Halve the Number of Trackable Users Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Raven Secures $20M to Enhance Cloud Security Solutions
  • Enhancing Security with Ceros for Claude Code
  • Iran-Linked Botnet Unveiled Through Open Directory Leak
  • CISA Highlights SharePoint Security Vulnerability Exploitation
  • DarkSword iOS Kit Exploits Multiple Flaws for Device Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Raven Secures $20M to Enhance Cloud Security Solutions
  • Enhancing Security with Ceros for Claude Code
  • Iran-Linked Botnet Unveiled Through Open Directory Leak
  • CISA Highlights SharePoint Security Vulnerability Exploitation
  • DarkSword iOS Kit Exploits Multiple Flaws for Device Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark