Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-28. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
SharePoint + Pre-Auth RCE + MemShell? 👀
We’ve published our technical analysis of CVE-2026-65660, covering the attack chain from an Allow Anonymous site and a pre-auth SharePoint vulnerability to RCE and MemShell.
Take a look:
https://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/ https://t.co/cHP0XVl9i8
‼️ ALERT - Microsoft initially classified CVE-2026-65660 as a SharePoint spoofing flaw. It actually enables authenticated RCE.
No in-the-wild exploitation has been reported "yet," but the full exploit markup is now public.
Here's how it works → https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
🛡️We added Microsoft SharePoint vulnerability CVE-2026-65660 & Mikrotik RouterOS vulnerability CVE-2026-67279 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/guGyzPoPIm
For allow anonymous sites, this is preauth RCE.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
Post summary
The message highlights that CVE-2026-65660 is a preauthentication RCE affecting sites permitting anonymous access, referencing Microsoft’s update guide for details.
🚨 SHAREPOINT FLAW MICROSOFT INITIALLY TREATED AS “SPOOFING” IS ACTUALLY RCE — WORKING EXPLOIT DETAILS NOW PUBLIC
New technical research on CVE-2026-65660 shows the SharePoint Server vulnerability can provide authenticated remote code execution, substantially changing the operational risk from Microsoft's earlier spoofing characterization.
• CVE-2026-65660 — CVSS 8.8 High in the current CVE record
• Affects on-premises SharePoint Server 2016, 2019 and Subscription Edition
• A low-privileged authenticated attacker can bypass SharePoint's SafeControls protection and register arbitrary .NET classes
• The exploit chain reaches code execution through XamlServices.Parse() deserialization
• The researcher demonstrated an in-memory webshell, reducing reliance on an obvious webshell file on disk
• Full exploit markup is now public, lowering the barrier to reproduction
• The flaw can also be chained with a separate authentication bypass on servers permitting anonymous page access — but that pre-authentication path was patched in June
• Microsoft's August 11 updates fix CVE-2026-65660 and disable the vulnerable functionality by default
• No confirmed in-the-wild exploitation has been identified at this time
⚠️ Analyst Note:
The unusual part is the vulnerability-triage gap. Organizations that deprioritized this issue when it appeared as a moderate spoofing flaw may now have an internet-facing SharePoint RCE with working technical details publicly available.
This matters even more because SharePoint has repeatedly moved quickly from technical disclosure to real-world exploitation. Defenders should verify the August update rather than rely on the original vulnerability label.
Official CVE record:
https://www.cve.org/CVERecord?id=CVE-2026-65660
#SharePoint#Microsoft#CVE202665660#RCE#Vulnerability#ThreatIntel#DDW#DarkWeb
Previdian observed SharePoint exploit attempts chaining CVE-2026-65660 (authenticated) with a separate anonymous delivery bug documented by @vcslab.
Attempts were carrying an encrypted .NET loader. Anonymous viewing required. https://t.co/Ca7MzL3iY9
A code-injection flaw Microsoft initially rated as "spoofing" turned out to be full remote code execution (CVSS 8.8).
CVE-2026-65660 lets a low-privileged, authenticated attacker execute code on SharePoint Server by exploiting an unescaped quote in how ToolPane reconstructs Register directives, bypassing SafeControls entirely. A researcher's public writeup includes a working exploit and shows it can chain with a separate (already-patched) bug for pre-auth RCE.
On CISA's KEV list. Remediate by Sep 28, 2026.
Details: http://vulntracker.io/cves/CVE-2026-65660
#Microsoft#SharePoint#CVE#InfoSec#CyberSecurity
Canadian Centre for Cyber Security@cybercentre_ca·
#CyberAlert | AL26-023 - Vulnerability Impacting Microsoft SharePoint Server
Organizations running affected Microsoft SharePoint Server deployments should update affected systems immediately.
https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660 https://t.co/4pWYZkAwAM
It’s Friday. SharePoint reviewed your request for a quiet weekend and selected Decline
CVE-2026-65660 is an 8.8 authenticated RCE. Canada’s Cyber Centre put out an active-exploitation alert yesterday
The asterisk: attackers can chain it with another SharePoint weakness and try code execution before login on sites that still allow anonymous viewing. So “it requires authentication” is doing a lot of unpaid overtime
SharePoint has had a busy year. 108 product-specific CVEs in 12 months. 7 Critical. 53 High
“We patched it a while ago” is not a build number.
Patch the farm. Kill anonymous access you don’t need. Check whether someone got in before the patch. Then go enjoy Friday. Hopefully SharePoint lets you.
An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now.
#SharePoint#CVE202665660#RCE#Cybersecurity#Infosec#ZeroDay
https://securityonline.info/exploited-sharepoint-rce-vulnerability/
Someone with a low-priv SharePoint login can run code on your on-prem farm. CISA put this on KEV today (due Sep 28).
Install the August SharePoint KBs:
https://hol.org/blog/cve-2026-65660-microsoft-sharepoint-code-injection-kev https://t.co/Mm0BYvSDtM
Microsoft rated CVE-2026-65660 as spoofing — CVSS 6.5. It's authenticated RCE on SharePoint — CVSS 8.8. PoC is public now. Security teams deprioritized an open door. Morphisec AMTD catches in-memory exploitation from IIS after your patch window closes. https://t.co/QXkRsYJJlD
🚨 MICROSOFT SHAREPOINT FLAW INITIALLY LISTED AS “SPOOFING” CAN ACTUALLY LEAD TO RCE
Researchers published new technical details for CVE-2026-65660.
The issue was originally categorized as a spoofing vulnerability.
Research now shows an authenticated attacker can potentially use it for remote code execution.
Microsoft patched the flaw on August 11.
There is currently:
✅ A patch
✅ Public technical detail
But:
❌ No known in-the-wild exploitation
❌ No CISA KEV listing
CyberSignal insight:
Severity labels don't always tell the entire story.
Sometimes exploitation research changes what defenders understand about a vulnerability after Patch Tuesday is over.
Source: Microsoft · The Hacker News
#Cybersecurity
CISA added Microsoft SharePoint CVE-2026-65660 to KEV. Code injection that lets an authorized attacker run code over the network; actively exploited. Patch per MSRC and check exposed farms for compromise. Federal due date 28 Sep.
🚨 SharePoint’s “spoofing” bug is now actively exploited—and patches have been out for weeks. Turns out a softer label doesn’t make attackers wait.
https://windowsforum.com/news/cve-2026-65660-cisa-flags-exploited-sharepoint-code-injection.446015/?utm_source=x&utm_medium=social&utm_campaign=news_node84
#Cybersecurity#CisaKev#MicrosoftSharepoint#MikrotikRouteros https://t.co/3n5TjrBiet