CRITICAL
CVE-2026-20963
CVSS
9.8
KEV
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Summary dbcve.org
This is a deserialization vulnerability in Microsoft Office SharePoint that allows an unauthorized (unauthenticated) attacker to execute arbitrary code remotely over a network. The critical CVSS score of 9.8 indicates ease of exploitation and complete impact on confidentiality, integrity, and availability.
Mitigation
Apply Microsoft security patches immediately upon release. Until a patch is available, restrict network access to SharePoint servers, implement WAF rules for deserialization payloads, and monitor for Indicators of Compromise.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
32.61%
Probability of exploitation in next 30 days
98.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.