Microsoft SharePoint and Exchange Server, already covered in this series for a five-CVE deserialization cluster earlier in 2026, produced four more confirmed-exploited vulnerabilities across the broader 365-day window — evidence that the pattern isn't a single incident but a sustained, recurring characteristic of these two platforms specifically.
CVE-2026-20963, CVSS 9.8, added 18 March 2026, is deserialization of untrusted data in SharePoint. CVE-2023-21529, CVSS 8.8, added 13 April 2026, is deserialization of untrusted data in Exchange Server — a 2023-disclosed vulnerability confirmed exploited nearly three years after its original disclosure. CVE-2026-32201, CVSS 6.5, added 14 April 2026, is improper input validation in SharePoint Server. CVE-2026-42897, CVSS 8.1, added 15 May 2026, is a cross-site scripting vulnerability in Exchange Server.
Why this keeps happening to these two products specifically
SharePoint and Exchange share more than a vendor — both are large, deeply feature-rich enterprise platforms with decades of accumulated functionality, both process substantial amounts of untrusted or semi-trusted content by design (documents, emails, attachments), and both have historically supported extensive customization and plugin ecosystems that expand the code surface well beyond what a security review of the core platform alone would cover. That combination — large attack surface, untrusted-content processing as a core function, and long product histories carrying forward code written under older security assumptions — is a reliable predictor of recurring critical vulnerabilities, and these two products satisfy it about as thoroughly as any enterprise software category does.
Why CVE-2023-21529's three-year gap deserves specific attention
An Exchange Server deserialization bug disclosed in 2023 only being confirmed as actively exploited in 2026 fits the pattern seen elsewhere in this series with older CVEs: the absence of a KEV listing at disclosure time was never proof the vulnerability wasn't valuable to attackers, only that exploitation hadn't yet been confirmed. Exchange Server in particular has a well-documented history as a high-value, heavily targeted platform — email infrastructure holds an enormous volume of sensitive organizational communication — which makes a three-year-old Exchange deserialization bug a plausible, patient target for a sophisticated actor content to wait for the right opportunity rather than exploit immediately upon disclosure.
What to check this week
Confirm patch status against all four CVEs specifically, not against a general sense of "we keep Exchange and SharePoint current" — the spread across nearly a year and multiple distinct root causes means partial patching is a real risk.
Give particular priority to CVE-2023-21529 if your Exchange patch history has any gaps reaching back to 2023. A three-year-old vulnerability now confirmed exploited means any unpatched instance has had an unusually long exposure window.
Audit custom SharePoint workflows, web parts, or Exchange transport rules for the same deserialization anti-pattern, given how consistently this specific vulnerability class recurs across both platforms — custom extensions built on the same underlying frameworks can carry equivalent, unpublicized flaws.
What organizations running both platforms should do differently
Many enterprises run SharePoint and Exchange together as part of the same Microsoft 365 or on-premises collaboration stack, which means a single-sign-on or shared-identity compromise through one platform's vulnerability can potentially extend into the other. Reviewing the actual identity and trust boundaries between these two systems — rather than assuming they operate as fully independent security domains simply because they're separate applications — is worth doing explicitly given how consistently both have appeared together in this year's confirmed-exploited findings.
A closing note on custom-code auditing cadence
Given how many custom SharePoint and Exchange extensions accumulate across a multi-year deployment, a periodic re-audit of custom code against current deserialization best practices deserves its own recurring schedule, rather than being folded into a one-time review that quickly falls out of date as customizations continue to be added.
A final consideration on migration to cloud-hosted alternatives
Organizations still running on-premises SharePoint or Exchange specifically because of legacy customization dependencies should weigh this cluster's history against the ongoing patching burden that history implies, as part of any broader evaluation of migrating to a cloud-hosted equivalent with a different patch-responsibility model.
How Safeguard helps
Safeguard's continuous inventory tracks recurring vulnerability patterns across a specific product line over time, surfacing exactly the kind of sustained, multi-incident history this SharePoint and Exchange cluster represents — context that should shift how these platforms are prioritized in an ongoing vulnerability management program, not just how any single CVE against them is triaged in isolation.