CVE-2026-65660 – High Code Injection RCE in Microsoft SharePoint Server

CVE-2026-65660 is a High severity (CVSS 8.8) code injection vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to execute arbitrary code over the network. Microsoft and CISA have confirmed active exploitation in the wild, and the flaw has been added to the CISA KEV catalog with a remediation deadline of September 28, 2026.

TL;DR

  • CVE-2026-65660 is a High (CVSS 8.8) code injection RCE in Microsoft SharePoint Server.
  • Active exploitation is confirmed; added to CISA KEV on September 25, 2026.
  • Attackers use a two-stage chain to deploy webshells; requires low-privilege authenticated access.
  • Affected versions include SharePoint Server 2016, 2019, and Subscription Edition.
  • Apply the vendor patch immediately and follow CISA BOD 26-04 guidance.

Overview

Microsoft SharePoint Server is currently under attack via CVE-2026-65660, a code injection flaw that bypasses input validation to allow remote code execution. While the vulnerability was initially classified as a spoofing issue, deeper analysis revealed it enables authenticated remote code execution with CVSS 8.8. The CISA KEV catalog entry marks this as a critical priority for federal and private-sector organizations alike.

Threat actors are not stopping at initial access. Intelligence gathered since late September 2026 indicates a two-stage attack methodology designed to establish persistence on compromised servers. The urgency is underscored by the CISA KEV inclusion date of September 25, 2026, and the required action deadline of September 28, 2026.

For key indicators, exploit activity over time, and detailed signal data, see the CVE page at https://vulnsocial.com/cve/CVE-2026-65660.


Technical Details

The vulnerability is classified as CWE-94 (Improper control of generation of code) within Microsoft Office SharePoint. The attack chain observed in the wild follows a distinct two-stage pattern:

  1. Initial Access: An attacker with low-privilege authenticated access submits crafted input that triggers code injection. This is not an unauthenticated zero-click exploit; valid credentials or an existing foothold are required.
  2. Persistence: Following code execution, attackers attempt to chain this with a secondary weakness to deploy a webshell, often targeting sites that allow anonymous access to maximize reach.

The initial misclassification of the flaw as a spoofing vulnerability adds risk, as some defense configurations may have been tuned for the wrong attack profile. Security teams should treat the CVE-2026-65660 exploit as an authenticated RCE regardless of initial vendor summaries.


Severity & Impact

MetricValue
CVSS Score8.8
SeverityHigh
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWECWE-94
CISA KEVYes

The CVSS vector indicates a network-based attack with low complexity, requiring only low privileges and no user interaction. Successful exploitation results in high impact across confidentiality, integrity, and availability. The CISA KEV designation confirms that this is not theoretical; exploitation is being observed actively.


Affected Products

Microsoft has identified the following SharePoint Server editions as affected:

  • SharePoint Server 2016
  • SharePoint Server 2019
  • SharePoint Subscription Edition

For the full list of affected products and versions, see CVE page.


Actionable Insights

Defenders should prioritize the following actions immediately:

  • Verify Patch Status: Check all SharePoint Server instances against the vendor patch release. Internet-facing instances are the highest priority.
  • Monitor for Webshells: Look for suspicious files in SharePoint web directories, particularly newly created files with executable extensions or encoded content.
  • Audit Authenticated Sessions: Review logs for low-privilege accounts performing unusual file operations or administrative actions following the September 22, 2026, spike in activity.
  • Check for Anonymous Sites: Identify SharePoint sites allowing anonymous access, as these are preferred targets for the second stage of the attack chain.
  • Track Threat Signals: For live threat activity and signal timelines, visit https://vulnsocial.com/cve/CVE-2026-65660.

Remediation & Mitigation

  1. Apply the patch: Install the latest security update from Microsoft for SharePoint Server 2016, 2019, or Subscription Edition as soon as possible. The vendor advisory is available at the MSRC update guide.
  2. Follow BOD 26-04: Organizations subject to CISA directives must adhere to BOD 26-04 Prioritizing Security Updates Based on Risk. The CISA KEV due date is September 28, 2026.
  3. Perform Forensic Triage: CISA requires forensics triage for CISA KEV vulnerabilities. Investigate affected assets for signs of webshell deployment or lateral movement.
  4. Restrict Anonymous Access: Disable anonymous access on SharePoint sites where not strictly required to reduce the attack surface for the persistence stage.
  5. Network Segmentation: Limit outbound traffic from SharePoint servers to prevent command-and-control communication if a webshell is present.

Bottom Line

CVE-2026-65660 is a High severity (CVSS 8.8) code injection RCE in Microsoft SharePoint Server under active exploitation. It has been added to the CISA KEV catalog with a remediation deadline of September 28, 2026. Apply the vendor patch, conduct forensic triage, and restrict anonymous access immediately.

#CVE202665660 #MicrosoftSharePoint #RCE #CISAKEV #Cybersecurity #ThreatIntel #SharePointServer #InfoSec