CISA added CVE-2026-20963, a Microsoft SharePoint deserialization-of-untrusted-data issue, to the KEV Catalog on March 18, 2026, citing evidence of active exploitation. CISA’s alert says the KEV Catalog is a living list of actively exploited CVEs and urges organizations to prioritize...