Cyber & AI intelligence
Wasteland.
Briefs indexed2875
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-65660 2026-09-25

Microsoft SharePoint Code Injection Flaw CVE-2026-65660 Under Active Exploitation

"CISA has added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog. The flaw is a high-severity code injection bug in on-premises Microsoft SharePoint Server that lets an authorized attacker execute code over…"

CISA has added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog. The flaw is a high-severity code injection bug in on-premises Microsoft SharePoint Server that lets an authorized attacker execute code over a network.

What Is It

CVE-2026-65660 is a code injection flaw (CWE-94) in Microsoft Office SharePoint. According to NVD, SharePoint does not properly control how it generates code. An attacker who is already authorized can use this to execute code over a network.

Microsoft rates it CVSS 3.1 8.8 (HIGH), vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. That means the attack works over the network, is low in complexity, needs only low privileges and requires no user interaction. A successful attack fully compromises confidentiality, integrity and availability.

NVD published the CVE on August 11, 2026.

Why It Matters

CISA added CVE-2026-65660 to the KEV catalog on September 25, 2026, which confirms active exploitation. CISA's SSVC assessment scores it as follows:

The KEV entry also marks it for forensic triage. Agencies must follow CISA's "Forensics Triage Requirements" as well as patching, which suggests CISA expects some systems may already be compromised. Known use in ransomware campaigns is listed as Unknown.

NVD also links a third-party advisory from Previdian titled "Previdian observes two-stage SharePoint exploitation attempts."

What's Vulnerable

According to the NVD affected-product data, these x64-based on-premises SharePoint versions are vulnerable:

Product Affected Versions
SharePoint Enterprise Server 2016 16.0.0 to before 16.0.5565.1001
SharePoint Server 2019 16.0.0 to before 16.0.10417.20198
SharePoint Server Subscription Edition 16.0.0 to before 16.0.19725.20522

Patch Status

Microsoft's advisory in the MSRC Update Guide is tagged as a patch reference. Updating to or beyond the fixed build listed above for each product addresses the flaw.

CISA's required action:

The federal remediation due date is September 28, 2026, three days after the KEV listing.

Sources