{"id":11457,"date":"2026-03-19T10:03:40","date_gmt":"2026-03-19T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/19\/cisa-warns-of-microsoft-sharepoint-vulnerability-exploited-in-attacks\/"},"modified":"2026-03-19T10:03:40","modified_gmt":"2026-03-19T10:03:40","slug":"cisa-warns-of-microsoft-sharepoint-vulnerability-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/19\/cisa-warns-of-microsoft-sharepoint-vulnerability-exploited-in-attacks\/","title":{"rendered":"CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks"},"content":{"rendered":"<p>    CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical security flaw in Microsoft SharePoint has been identified as actively exploited, and on March 18, 2026, the vulnerability was officially added to the Known Exploited Vulnerabilities (KEV) catalog.<\/p>\n<p>This addition confirms that threat actors are actively exploiting the flaw in real-world network attacks, <a href=\"https:\/\/cybersecuritynews.com\/ransomware-attack-2025-recap\/\" target=\"_blank\" rel=\"noreferrer noopener\">prompting an urgent call to action for all network administrators<\/a> who rely on the collaboration platform.<\/p>\n<p>Tracked formally as CVE-2026-20963, this security weakness stems from how <a href=\"https:\/\/cybersecuritynews.com\/deserialization-vulnerability-in-ruby\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft SharePoint handles the deserialization of untrusted data.<\/a><\/p>\n<p>Deserialization is the process by which software converts data structured for storage or network transfer back into live, executable objects in the application\u2019s memory.<\/p>\n<p>When an application fails to verify the safety of incoming data properly, attackers can exploit the process. In this specific SharePoint vulnerability, an unauthorized, remote attacker can carefully <a href=\"https:\/\/cybersecuritynews.com\/apache-activemq-dos-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">craft a malicious data packet <\/a>and send it to a vulnerable server over the network.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-microsoft-sharepoint-vulnerability\"><strong>Microsoft SharePoint Vulnerability <\/strong><\/h2>\n<p>When SharePoint attempts to deserialize this untrusted input, it inadvertently triggers the attacker\u2019s embedded instructions.<\/p>\n<p>This flaw enables a threat actor to execute arbitrary code on the host machine without requiring valid user credentials.<\/p>\n<p>Because SharePoint environments typically house highly sensitive enterprise documents and internal communications, a successful remote code execution attack could <a href=\"https:\/\/cybersecuritynews.com\/data-breach-at-texas-gas-station-operator-exposes\/\" target=\"_blank\" rel=\"noreferrer noopener\">result in a devastating corporate data breach<\/a>.<\/p>\n<p>CISA\u2019s decision to add CVE-2026-20963 to the KEV catalog indicates that cybersecurity defenders have observed active exploitation in the wild.<\/p>\n<p>While security researchers have confirmed the ongoing attacks, <a href=\"https:\/\/cybersecuritynews.com\/advanced-persistent-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">the specific advanced persistent threat (APT) groups<\/a> behind these campaigns currently remain unidentified.<\/p>\n<p>Furthermore, CISA notes that the vulnerability\u2019s involvement in active ransomware campaigns is presently unknown. However, remote code execution flaws are highly prized by <a href=\"https:\/\/cybersecuritynews.com\/us-sanctions-exploit-brokers\/\" target=\"_blank\" rel=\"noreferrer noopener\">initial access brokers and ransomware syndicates<\/a>.<\/p>\n<p>Once code execution is achieved, attackers can easily deploy secondary payloads, establish persistent backdoors, and move laterally across the broader corporate network to launch extortion campaigns.<\/p>\n<p>To mitigate the risk of widespread compromise, <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-20963\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA has issued strict directives for Federal Civilian Executive Branch (FCEB) agencies<\/a>.<\/p>\n<p>Under Binding Operational Directive (BOD) 22-01, federal organizations face an exceptionally tight remediation window. All vulnerable instances of Microsoft SharePoint must be completely patched or mitigated by March 21, 2026.<\/p>\n<p>Private-sector organizations are strongly encouraged to adopt this aggressive timeline to protect their digital infrastructure.<\/p>\n<p>Administrators must immediately review <a href=\"https:\/\/cybersecuritynews.com\/github-copilot-and-visual-studio-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft\u2019s official security advisories and apply all available security updates<\/a>.<\/p>\n<p>If immediate patching is technically impossible within the environment, organizations must apply vendor-supplied mitigations.<\/p>\n<p>If no alternative mitigations are available, CISA explicitly advises network defenders to discontinue use of the vulnerable product entirely until a permanent fix can be safely implemented.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-sharepoint-vulnerability-exploited\/\">CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-sharepoint-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks A critical security flaw in Microsoft SharePoint has been identified as actively exploited, and on March 18, 2026, the vulnerability was officially added to the Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that threat actors are actively exploiting the flaw in real-world network attacks, prompting [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11457","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11457"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11457"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11457\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}