CVE-2026-20963
exploited in the wild☆ pinCVSS
9.8
Reports
3
First seen
Mar 24, 2026
Last seen
Apr 13, 2026
Affected product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Associated actors
Recent reports
Critical