CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
— CISA
Microsoft SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5535.1001Patch KB5002828 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19127.20442Patch KB5002822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20083Patch KB5002825
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20963?
CVE-2026-20963 has a CVSS score that indicates it is a critical remote code execution vulnerability.
How does CVE-2026-20963 affect Microsoft SharePoint?
CVE-2026-20963 allows an authorized attacker to execute arbitrary code over a network by exploiting deserialization of untrusted data in Microsoft SharePoint.
How do I fix CVE-2026-20963?
To fix CVE-2026-20963, apply the latest security patches provided by Microsoft for the affected SharePoint versions.
What versions of SharePoint are affected by CVE-2026-20963?
CVE-2026-20963 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
What should I do if I can't patch against CVE-2026-20963 immediately?
If immediate patching is not possible, implement network segmentation and restrict access to the SharePoint server to minimize exposure.