Story perspectives
Critical Microsoft SharePoint Vulnerability Added to CISA's List
3/21/2026
24 6
1 of 1
Story summary
- Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft SharePoint vulnerability CVE-2026-20963 to its Known Exploited Vulnerabilities list, labeling it critical.
- The flaw enables unauthenticated attackers to remotely execute arbitrary code by deserializing untrusted data.
- Federal agencies must remediate CVE-2026-20963 by March 21, 2026.
- Separately, Synacor Zimbra Collaboration Suite has a stored cross-site scripting flaw, CVE-2025-66376, with remediation due by April 1, 2026.
