certeu-2026-004

certeu
Description

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026.<br> Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release.<br> CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions.<br>

Timeline
Published
Wed, 25 Mar 2026 08:51:39 CET
Last Modified
Wed, 25 Mar 2026 08:51:39 CET
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "datePublished": "Wed, 25 Mar 2026 08:51:39 CET",
  "description": "On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026.<br>\nAdditionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release.<br>\nCERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions.<br>",
  "id": "CERTEU-2026-004",
  "link": "https://cert.europa.eu/publications/security-advisories/2026-004/",
  "source": "certeu",
  "title": "2026-004: Critical Vulnerability in SharePoint Exploited"
}
View JSON API Download JSON