CVE-2026-65660Disclosure(microsoft / sharepoint_server)

LOWCVSS 8.8 · HIGHCISA KEV

Signal is active with 8 mentions in latest observed window

Immediate actions

  • Patch microsoft sharepoint_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-28. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Patch or workaround signal is available
  • 58 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 18 mentions (2026-09-25); latest day: 8
  • 58 total mentions across 6 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline58 mentions / 6d
0591418Mentions · 2026-08-12: 2Mentions · 2026-09-22: 17Mentions · 2026-09-23: 5Mentions · 2026-09-24: 8Mentions · 2026-09-25: 18Mentions · 2026-09-26: 8Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 208-1209-2209-2309-2409-2509-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets45 URLs
By indicator
Full discourse20 posts
  • Khoa Dinh@_l0gg

    SharePoint + Pre-Auth RCE + MemShell? 👀 We’ve published our technical analysis of CVE-2026-65660, covering the attack chain from an Allow Anonymous site and a pre-auth SharePoint vulnerability to RCE and MemShell. Take a look: https://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/ https://t.co/cHP0XVl9i8

    10144161332832.3K
    2.4K followersView on X
  • The Hacker News@TheHackersNews

    ‼️ ALERT - Microsoft initially classified CVE-2026-65660 as a SharePoint spoofing flaw. It actually enables authenticated RCE. No in-the-wild exploitation has been reported "yet," but the full exploit markup is now public. Here's how it works → https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html

    74321506848.8K
    2.4M followersView on X
  • CISA Cyber@CISACyber

    🛡️We added Microsoft SharePoint vulnerability CVE-2026-65660 & Mikrotik RouterOS vulnerability CVE-2026-67279 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/guGyzPoPIm

    31513476.7K
    302.7K followersView on X
  • Khoa Dinh@_l0gg
    Disclosure

    For allow anonymous sites, this is preauth RCE. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660

    Post summary

    The message highlights that CVE-2026-65660 is a preauthentication RCE affecting sites permitting anonymous access, referencing Microsoft’s update guide for details.

    12045124.0K
    2.3K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 SHAREPOINT FLAW MICROSOFT INITIALLY TREATED AS “SPOOFING” IS ACTUALLY RCE — WORKING EXPLOIT DETAILS NOW PUBLIC New technical research on CVE-2026-65660 shows the SharePoint Server vulnerability can provide authenticated remote code execution, substantially changing the operational risk from Microsoft's earlier spoofing characterization. • CVE-2026-65660 — CVSS 8.8 High in the current CVE record • Affects on-premises SharePoint Server 2016, 2019 and Subscription Edition • A low-privileged authenticated attacker can bypass SharePoint's SafeControls protection and register arbitrary .NET classes • The exploit chain reaches code execution through XamlServices.Parse() deserialization • The researcher demonstrated an in-memory webshell, reducing reliance on an obvious webshell file on disk • Full exploit markup is now public, lowering the barrier to reproduction • The flaw can also be chained with a separate authentication bypass on servers permitting anonymous page access — but that pre-authentication path was patched in June • Microsoft's August 11 updates fix CVE-2026-65660 and disable the vulnerable functionality by default • No confirmed in-the-wild exploitation has been identified at this time ⚠️ Analyst Note: The unusual part is the vulnerability-triage gap. Organizations that deprioritized this issue when it appeared as a moderate spoofing flaw may now have an internet-facing SharePoint RCE with working technical details publicly available. This matters even more because SharePoint has repeatedly moved quickly from technical disclosure to real-world exploitation. Defenders should verify the August update rather than rely on the original vulnerability label. Official CVE record: https://www.cve.org/CVERecord?id=CVE-2026-65660 #SharePoint #Microsoft #CVE202665660 #RCE #Vulnerability #ThreatIntel #DDW #DarkWeb

    030736.9K
    205.0K followersView on X
  • Previdian@PrevidianCyber

    Previdian observed SharePoint exploit attempts chaining CVE-2026-65660 (authenticated) with a separate anonymous delivery bug documented by @vcslab. Attempts were carrying an encrypted .NET loader. Anonymous viewing required. https://t.co/Ca7MzL3iY9

    121701.7K
    67 followersView on X
  • VulnTracker@vuln_tracker

    A code-injection flaw Microsoft initially rated as "spoofing" turned out to be full remote code execution (CVSS 8.8). CVE-2026-65660 lets a low-privileged, authenticated attacker execute code on SharePoint Server by exploiting an unescaped quote in how ToolPane reconstructs Register directives, bypassing SafeControls entirely. A researcher's public writeup includes a working exploit and shows it can chain with a separate (already-patched) bug for pre-auth RCE. On CISA's KEV list. Remediate by Sep 28, 2026. Details: http://vulntracker.io/cves/CVE-2026-65660 #Microsoft #SharePoint #CVE #InfoSec #CyberSecurity

    10051300
    770 followersView on X
  • Previdian@PrevidianCyber

    Write up 👇 https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/

    03040304
    67 followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca

    #CyberAlert | AL26-023 - Vulnerability Impacting Microsoft SharePoint Server Organizations running affected Microsoft SharePoint Server deployments should update affected systems immediately. https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660 https://t.co/4pWYZkAwAM

    12020607
    34.0K followersView on X
  • ThreatHunter.ai@ThreatHunter_AI

    It’s Friday. SharePoint reviewed your request for a quiet weekend and selected Decline CVE-2026-65660 is an 8.8 authenticated RCE. Canada’s Cyber Centre put out an active-exploitation alert yesterday The asterisk: attackers can chain it with another SharePoint weakness and try code execution before login on sites that still allow anonymous viewing. So “it requires authentication” is doing a lot of unpaid overtime SharePoint has had a busy year. 108 product-specific CVEs in 12 months. 7 Critical. 53 High “We patched it a while ago” is not a build number. Patch the farm. Kill anonymous access you don’t need. Check whether someone got in before the patch. Then go enjoy Friday. Hopefully SharePoint lets you.

    02020134
    5.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now. #SharePoint #CVE202665660 #RCE #Cybersecurity #Infosec #ZeroDay https://securityonline.info/exploited-sharepoint-rce-vulnerability/

    10021376
    13.0K followersView on X
  • Previdian@PrevidianCyber

    https://previdian.com/CVE-2026-65660

    12010149
    67 followersView on X
  • HOL@HashgraphOnline

    Someone with a low-priv SharePoint login can run code on your on-prem farm. CISA put this on KEV today (due Sep 28). Install the August SharePoint KBs: https://hol.org/blog/cve-2026-65660-microsoft-sharepoint-code-injection-kev https://t.co/Mm0BYvSDtM

    11100633
    19.2K followersView on X
  • kokumօtօ@__kokumoto

    Sharepointにおけるなりすましの脆弱性CVE-2026-65660が遠隔コード実行に見直しされている。CVSSスコアは6.5から8.8に。8/11定例更新で修正されたもので、MSRCの記載は8/27見直し。 https://thecyberexpress.com/cve-2026-65660-sharepoint-rce-flaw/

    00021798
    7.8K followersView on X
  • NotCVE@notCVE

    ⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-09-25 CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability CVSS 8.8 · EPSS 1.2% · 1 public exploit Details, versions & intel → https://notcve.org/cve/CVE-2026-65660 https://t.co/xKJSos8HvP

    1001052
    73 followersView on X
  • Morphisec@morphisec

    Microsoft rated CVE-2026-65660 as spoofing — CVSS 6.5. It's authenticated RCE on SharePoint — CVSS 8.8. PoC is public now. Security teams deprioritized an open door. Morphisec AMTD catches in-memory exploitation from IIS after your patch window closes. https://t.co/QXkRsYJJlD

    00011144
    2.3K followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX

    🚨 MICROSOFT SHAREPOINT FLAW INITIALLY LISTED AS “SPOOFING” CAN ACTUALLY LEAD TO RCE Researchers published new technical details for CVE-2026-65660. The issue was originally categorized as a spoofing vulnerability. Research now shows an authenticated attacker can potentially use it for remote code execution. Microsoft patched the flaw on August 11. There is currently: ✅ A patch ✅ Public technical detail But: ❌ No known in-the-wild exploitation ❌ No CISA KEV listing CyberSignal insight: Severity labels don't always tell the entire story. Sometimes exploitation research changes what defenders understand about a vulnerability after Patch Tuesday is over. Source: Microsoft · The Hacker News #Cybersecurity

    0101052
    228 followersView on X
  • Arnav Sharma 🇦🇺@arnavsharma

    CISA added Microsoft SharePoint CVE-2026-65660 to KEV. Code injection that lets an authorized attacker run code over the network; actively exploited. Patch per MSRC and check exposed farms for compromise. Federal due date 28 Sep.

    1000058
    2.2K followersView on X
  • Batou@toushikaka

    【朝のセキュリティ】脅威動向 (2026-09-26) 今日の焦点は、外部公開された境界機器・サーバーで実際に悪用が進んでいる脆弱性です。SharePoint、MikroTikルータ、Check Pointの3件は、パッチ適用に加えて侵害痕跡の確認まで必要です。 🚨 脆弱性・パッチ 🔴 Microsoft SharePoint → CVE-2026-65660 / CVSS 8.8。9/25にCISA KEV(悪用確認済み脆弱性の米政府リスト)に追加。8月の更新で修正済みだが、当初は「なりすまし(CVSS 6.5)」と分類され、実際は認証済みRCE(遠隔からのコード実行)だった。分類を見て後回しにした組織は8月更新の適用状況を再確認。2013/2016/2019/Subscription Editionが対象 🔴 MikroTik RouterOS → CVE-2026-67279(SSH鍵再交換時の認証バイパス)とCVE-2026-86060(ログイン処理の引数注入)の連鎖で、パスワードなしに管理者権限を奪われる。9/25にCVE-2026-67279もKEV入り。修正版は6.49.21 / 7.23.4 / 7.24.2。パッチ前(9/2頃)から悪用されていたため、更新後もユーザー名「-2」のログイン失敗記録、不審な管理者アカウント「ops」、/system/device-mode/printのFlagged表示を確認する 🔴 Check Point → Security GatewayのVPN証明書処理の欠陥CVE-2026-85102(CVSS 9.8、9/9修正済み)が9/12以降悪用中。管理サーバー側では未知の脆弱性CVE-2026-93616(CVSS 9.8)の限定的な悪用も確認され、修正が公開された。LivePatch Take 28/29では直らない点に注意(sk1000171) 🕵️ 攻撃・インシデント 🟡 MemTensorのnpm/PyPIパッケージ乗っ取り → GitHub Actionsの公開用トークンが奪われ、認証情報窃取マルウェア「sckit」入りの版が配布された。対象は@memtensor/memos-cloud-openclaw-plugin 0.1.21/0.1.23/0.1.25とMemoryOS 2.0.34。導入環境は安全な版に固定し、開発端末とCIの秘密情報をすべて入れ替える ・AIエージェントによるEC攻撃 → オープンソースのAIエージェント群で脆弱性探索から侵入までを自動化し、7月以降、数百のネットショップを攻撃。60万件超のカード情報が盗まれたと報じられている(報道ベース)。1社あたりの攻撃コストは約25ドルとの試算 ・Microsoft 365へのパスワード総当たり → Proofpointによると、ツール「TeamFiltration」を使った攻撃で28テナントの5,700超のアカウントが狙われた。侵害された7件はすべて、MFA(多要素認証)のない放置された共用・サービスアカウントだった。人に紐づかないアカウントの棚卸しが有効 📜 規制・当局の動き ・米CIRCIA(重要インフラ向けサイバー事案報告法)→ CISAは9月中の最終規則公表を目標としてきた。重大事案は72時間以内、身代金支払いは24時間以内の報告が柱。9/26時点で最終規則の公表は確認できていない #サイバーセキュリティ #脆弱性 #セキュリティ

    00010258
    160 followersView on X
  • Windows Forum@windowsforum

    🚨 SharePoint’s “spoofing” bug is now actively exploited—and patches have been out for weeks. Turns out a softer label doesn’t make attackers wait. https://windowsforum.com/news/cve-2026-65660-cisa-flags-exploited-sharepoint-code-injection.446015/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #Cybersecurity #CisaKev #MicrosoftSharepoint #MikrotikRouteros https://t.co/3n5TjrBiet

    1000053
    1.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more