CISA has added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog. The flaw is a high-severity code injection bug in on-premises Microsoft SharePoint Server that lets an authorized attacker execute code over a network.
What Is It
CVE-2026-65660 is a code injection flaw (CWE-94) in Microsoft Office SharePoint. According to NVD, SharePoint does not properly control how it generates code. An attacker who is already authorized can use this to execute code over a network.
Microsoft rates it CVSS 3.1 8.8 (HIGH), vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. That means the attack works over the network, is low in complexity, needs only low privileges and requires no user interaction. A successful attack fully compromises confidentiality, integrity and availability.
NVD published the CVE on August 11, 2026.
Why It Matters
CISA added CVE-2026-65660 to the KEV catalog on September 25, 2026, which confirms active exploitation. CISA's SSVC assessment scores it as follows:
- Exploitation: active
- Automatable: no
- Technical impact: total
The KEV entry also marks it for forensic triage. Agencies must follow CISA's "Forensics Triage Requirements" as well as patching, which suggests CISA expects some systems may already be compromised. Known use in ransomware campaigns is listed as Unknown.
NVD also links a third-party advisory from Previdian titled "Previdian observes two-stage SharePoint exploitation attempts."
What's Vulnerable
According to the NVD affected-product data, these x64-based on-premises SharePoint versions are vulnerable:
| Product | Affected Versions |
|---|---|
| SharePoint Enterprise Server 2016 | 16.0.0 to before 16.0.5565.1001 |
| SharePoint Server 2019 | 16.0.0 to before 16.0.10417.20198 |
| SharePoint Server Subscription Edition | 16.0.0 to before 16.0.19725.20522 |
Patch Status
Microsoft's advisory in the MSRC Update Guide is tagged as a patch reference. Updating to or beyond the fixed build listed above for each product addresses the flaw.
CISA's required action:
- Apply mitigations according to vendor instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements.
- Follow the applicable BOD 26-04 guidance for cloud services, or stop using the product if no mitigations are available.
- Check each asset's internet exposure and keep to the BOD 26-04 patching guidelines.
The federal remediation due date is September 28, 2026, three days after the KEV listing.
Sources
- CISA Known Exploited Vulnerabilities Catalog – CVE-2026-65660
- NVD – CVE-2026-65660
- Microsoft Security Response Center – CVE-2026-65660
- Previdian – Two-Stage SharePoint Exploitation Attempts
- CISA BOD 26-04 – Prioritizing Security Updates Based on Risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements)