<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cisa-Kev — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cisa-kev/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 20 Mar 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cisa-kev/feed.xml" rel="self" type="application/rss+xml"/><item><title>Active Exploitation of SharePoint Deserialization Vulnerability (CVE-2026-20963)</title><link>https://feed.craftedsignal.io/briefs/2026-03-sharepoint-deserialization/</link><pubDate>Fri, 20 Mar 2026 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-sharepoint-deserialization/</guid><description>CVE-2026-20963, a SharePoint deserialization vulnerability, is under active exploitation and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, requiring immediate patching and auditing of potentially compromised data.</description><content:encoded>&lt;p>On March 18, 2026, CISA added CVE-2026-20963, a SharePoint deserialization vulnerability, to its Known Exploited Vulnerabilities catalog, signaling active exploitation in the wild. This vulnerability allows attackers to execute arbitrary code on affected SharePoint servers through the deserialization of untrusted data. Organizations utilizing SharePoint are urged to apply the necessary patches promptly. Beyond patching, it&amp;rsquo;s crucial to conduct a thorough audit of SharePoint assets, particularly…&lt;/p>
</content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>CVE-2026-20963</category><category>sharepoint</category><category>deserialization</category><category>cisa-kev</category></item></channel></rss>