Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical SharePoint Flaw Enables Remote Code Execution

Critical SharePoint Flaw Enables Remote Code Execution

Posted on September 22, 2026 By CWS

Microsoft has identified a significant security vulnerability in its on-premises SharePoint Server, which allows authenticated users with minimal privileges to execute arbitrary code remotely. This high-severity flaw, identified as CVE-2026-65660, poses a risk to servers running SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, with a CVSS score of 8.8.

Technical Details of the Vulnerability

The vulnerability was brought to light by Viettel Cyber Security’s Dinh Ho Anh Khoa, who highlighted it as a bypass of SharePoint’s SafeControls, a mechanism designed to prevent the instantiation of untrusted server-side classes. The flaw is triggered when the ToolPane component processes Register directives that map tag prefixes to ASP.NET controls.

During processing, ToolPane separates directives from markup and verifies their types. However, the reconstruction of these directives fails to escape embedded quotation marks, allowing malicious values to alter the directive. This error makes it possible for attackers to register dangerous .NET classes and execute arbitrary code.

Impact and Exploitation

Successful exploitation of this flaw could lead to credential theft, lateral movement within networks, and data exfiltration. Although Microsoft states that authentication is necessary for exploitation and that the risk of pre-authentication remote code execution (RCE) was mitigated in a June 2026 update, the public availability of technical details lowers the barrier for potential attacks.

Researchers have demonstrated the potential for creating in-memory webshells, which avoid writing to disk and complicate detection and response efforts. This sophisticated technique underscores the need for organizations to remain vigilant and proactive in their security measures.

Advisory and Mitigation Steps

Microsoft released patches on August 11, 2026, to address the issue, urging organizations to apply updates immediately. Administrators should ensure that all relevant updates are installed, especially for SharePoint 2016, which may require additional packages. Systems still running SharePoint 2013, which is no longer supported, should consider urgent migration or isolation.

To mitigate risk, administrators are advised to limit internet and anonymous access, review low-privilege accounts, and monitor for suspicious activity such as unusual Web Part markup or encoded XAML in POST requests. Furthermore, response teams should examine worker-process behaviors and preserve key logs and telemetry data during investigations.

Despite Microsoft’s assessment that exploitation is unlikely, the public dissemination of detailed information means that organizations must act swiftly to secure their systems against potential threats.

Cyber Security News Tags:CVE-2026-65660, Cybersecurity, data protection, enterprise security, IT security, Microsoft, network security, patch management, remote code execution, security updates, server security, SharePoint, software flaw, Vulnerability

Post navigation

Previous Post: Cyera Secures $400M, Reaches $12B Valuation
Next Post: SharePoint Vulnerability Allows Remote Code Execution

Related Posts

Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security Cyber Security News
Microsoft Investigates Defender Portal Access Issues Following Traffic Spike Microsoft Investigates Defender Portal Access Issues Following Traffic Spike Cyber Security News
Threat Actors Leveraging GenAI for Phishing Attacks Impersonating Government Websites Threat Actors Leveraging GenAI for Phishing Attacks Impersonating Government Websites Cyber Security News
Mysterious Ox Alpha AI Offers Free Tokens to Coders Mysterious Ox Alpha AI Offers Free Tokens to Coders Cyber Security News
Microsoft December 2025 Patch Tuesday Microsoft December 2025 Patch Tuesday Cyber Security News
21,000+ OpenClaw AI Instances With Personal Configurations Exposed Online 21,000+ OpenClaw AI Instances With Personal Configurations Exposed Online Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark