CRITICAL

CVE-2026-20963

Microsoft Sharepoint Server 2026-01-13 CVSS v3.1
CVSS
9.8
KEV

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Summary dbcve.org

This is a deserialization vulnerability in Microsoft Office SharePoint that allows an unauthorized (unauthenticated) attacker to execute arbitrary code remotely over a network. The critical CVSS score of 9.8 indicates ease of exploitation and complete impact on confidentiality, integrity, and availability.

Mitigation

Apply Microsoft security patches immediately upon release. Until a patch is available, restrict network access to SharePoint servers, implement WAF rules for deserialization payloads, and monitor for Indicators of Compromise.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

32.61%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE