Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

2026-004: Critical Vulnerability in SharePoint Exploited

CERT-EU Version 1 original

Imported from official source

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon...

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
d0903ad67501cde1c4769f0eccee7271
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.