A vulnerability in Microsoft’s SharePoint, identified as CVE-2026-65660, is currently being exploited in active attacks. This development comes about six weeks after Microsoft issued patches and shortly after researchers released technical details about the flaw.
Details of the CVE-2026-65660 Vulnerability
The vulnerability, addressed by Microsoft in its August 2026 Patch Tuesday updates, is a remote code execution issue. It allows an attacker with low-level access to execute arbitrary code on an affected server without any user interaction. This was highlighted in Microsoft’s advisory, which categorized the flaw as a critical code injection vulnerability.
On September 25, 2026, Microsoft confirmed that they had observed real-world exploitation of CVE-2026-65660. Consequently, the Cybersecurity and Infrastructure Security Agency (CISA) included this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by September 28.
Evidence of Exploitation
Previdian, an early-warning threat intelligence platform formerly known as KEVIntel, reported seeing exploitation attempts as early as September 24. By the following day, there were attempts to install a webshell backdoor, indicating the severity of the threat.
The identity of the attackers remains unknown, but the attacks commenced shortly after Viettel Security, which initially reported the flaw to Microsoft, disclosed technical details. Initially, Microsoft classified the flaw as a medium-severity spoofing issue before elevating it to a high-severity remote code execution vulnerability.
Understanding the Vulnerability’s Impact
This vulnerability is considered an authenticated flaw, requiring attackers to have low-level privileges but not needing user interaction. Alone, it functions as a type-check bypass that can be leveraged for code execution by an authenticated attacker. However, to achieve unauthenticated remote code execution, it must be combined with another authentication bypass vulnerability.
Previdian noted that the observed exploits appear to be informed by the technical information released by Viettel. CISA’s KEV catalog now lists 16 SharePoint vulnerabilities, with eight discovered and patched in the current year.
The urgency of patching this vulnerability is underscored by the speed and sophistication of its exploitation in the wild, emphasizing the critical need for organizations to implement Microsoft’s security updates promptly.
