April "In the Trend of VM" (#26): one Microsoft SharePoint vulnerability. Presenting the traditional monthly roundup of trending vulnerabilities by Positive Technologies. Once again, single-vendor, Microsoft-focused, and unusually compact. While the previous March edition had four trending vulnerabilities, this April edition has only one. In the upcoming May edition, we expect at least three trending vulnerabilities. 😉
🗞 Post on Habr (rus)
🗒 Digest on the PT website (rus)
This vulnerability is from the January Microsoft Patch Tuesday:
🔻 RCE - Microsoft SharePoint (CVE-2026-20963). The vulnerability was initially rated less critical due to an authentication requirement PR:L, but Microsoft later determined that no authentication is required PR:N. It was added to the CISA KEV, indicating active exploitation in the wild. No public exploits exist yet.
🟥 The full list of trending vulnerabilities is available on the portal
@avleonovcom #PositiveTechnologies #TrendVulns #Microsoft #SharePoint #CISA #CISAKEV
Post #1651
546
