Threat Intel
Critical SharePoint RCE Exploit: Unauthenticated Attackers Target Internet‑Facing Servers
Microsoft’s March 2026 patch now flags a remote‑code‑execution flaw in SharePoint as exploitable by unauthenticated attackers, with a higher CVSS score. The vulnerability was added to CISA’s KEV catalogue and three additional RCE bugs were fixed. CERT‑EU urges all SharePoint hosts, especially those exposed to the internet, to apply the update immediately and perform full remediation.
Microsoft SharePoint RCE Vulnerability – What You Need to Know
On 17 March 2026, Microsoft revised its January advisory for a critical SharePoint remote code execution (RCE) flaw. The update increased the CVSS score and clarified that the issue can be triggered by an unauthenticated attacker.
Just one day later, the vulnerability was catalogued in CISA’s Known Exploited Vulnerabilities (KEV) list, signalling that active exploitation is occurring in the wild.
In the same March release, three additional RCE bugs affecting SharePoint were patched, underscoring a broader security issue across the platform.
CERT‑EU’s recommendation: Update all SharePoint servers without delay, prioritising those that are internet‑facing. Administrators should also review related configurations and apply any supplementary mitigations.
- Apply the latest March 2026 SharePoint patch.
- Verify that no legacy authentication methods remain enabled.
- Conduct a quick audit of exposed endpoints and firewall rules.
- Enable logging and monitor for anomalous activity.
"The updated CVSS score reflects the increased risk of unauthenticated exploitation, which is a serious concern for any publicly reachable SharePoint instance."
Failure to act promptly could expose sensitive data and give attackers a foothold for further lateral movement within corporate networks.