SharePoint CVE-2026-20963 Vulnerability Under Active Exploitation: CISA Issues March 21 Deadline for Critical Patch
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the SharePoint CVE-2026-20963 vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 18, confirming that attackers are actively exploiting the critical remote code execution flaw in the wild. Federal agencies have until March 21 to patch all vulnerable Microsoft SharePoint servers, while CISA strongly urges…
