TGViewer
Vulnerability Management and more Vulnerability Management and more @avleonovcom · 2.89K subscribers
Post #1651 546
April "In the Trend of VM" (#26): one Microsoft SharePoint vulnerability. Presenting the traditional monthly roundup of trending vulnerabilities by Positive Technologies. Once again, single-vendor, Microsoft-focused, and unusually compact. While the previous March edition had four trending vulnerabilities, this April edition has only one. In the upcoming May edition, we expect at least three trending vulnerabilities. 😉

🗞 Post on Habr (rus)
🗒 Digest on the PT website (rus)

This vulnerability is from the January Microsoft Patch Tuesday:

🔻 RCE - Microsoft SharePoint (CVE-2026-20963). The vulnerability was initially rated less critical due to an authentication requirement PR:L, but Microsoft later determined that no authentication is required PR:N. It was added to the CISA KEV, indicating active exploitation in the wild. No public exploits exist yet.

🟥 The full list of trending vulnerabilities is available on the portal

@avleonovcom #PositiveTechnologies #TrendVulns #Microsoft #SharePoint #CISA #CISAKEV
More from @avleonovcom
  1. Sep 14, 2026About Authentication Bypass - Microsoft SharePoint (CVE-2026-55040) vulnerability. SharePo…
  2. Sep 11, 2026About Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-688…
  3. Sep 9, 2026September Microsoft Patch Tuesday. A total of 973 vulnerabilities were addressed - more th…
  4. Sep 7, 2026About Remote Code Execution - TeamCity (CVE-2026-63077) vulnerability. TeamCity is a propr…
  5. Sep 4, 2026About Remote Code Execution - TrueConf Server (CVE-2026-72529, CVE-2026-72530) vulnerabili…
  6. Aug 31, 2026About Remote Code Execution - Zimbra Collaboration (CVE-2026-73570) vulnerability. Zimbra…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →