Federal News
CISA Mandates Federal Patch for Microsoft SharePoint
March 19, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical Microsoft SharePoint vulnerability (CVE-2026-20963) to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal Civilian Executive Branch (FCEB) agencies are mandated to patch or mitigate this vulnerability by March 21, 2026, to prevent remote code execution attacks that could compromise sensitive government data and systems. This directive follows the January 2026 patch release for affected SharePoint Server versions 2016, 2019, and Subscription Edition. While the mandate applies to federal agencies, private sector organizations are strongly encouraged to implement the patch promptly to reduce exposure to this critical security risk.
- Why this matters: Federal procurement and IT security teams must prioritize acquiring and deploying patch management services and cybersecurity solutions to meet the March 21 deadline.
- This mandate creates demand for vendors specializing in vulnerability assessment, patch deployment, and managed security services tailored to Microsoft SharePoint environments.
- Contractors supporting federal agencies should ensure compliance with CISA directives to avoid operational disruptions and potential security breaches.
- Organizations providing cybersecurity training and incident response services may find increased opportunities as agencies bolster defenses against active exploitation threats.
In a network-based attack, an unauthenticated attacker could write arbitrary code to inject and execute code remotely on the SharePoint Server.
— Microsoft
Agencies
Cybersecurity and Infrastructure Security Agency, Federal Civilian Executive Branch, Department of Homeland Security, Department of Energy, Department of Justice
Vendors
Microsoft
Locations
Sources
- CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks · CyberSecurityNews · Mar 19
- Critical Microsoft SharePoint flaw now exploited in attacks · BleepingComputer · Mar 19