Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack

Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack

Posted on September 27, 2026 By CWS

A vulnerability in Microsoft’s SharePoint, identified as CVE-2026-65660, is currently being exploited in active attacks. This development comes about six weeks after Microsoft issued patches and shortly after researchers released technical details about the flaw.

Details of the CVE-2026-65660 Vulnerability

The vulnerability, addressed by Microsoft in its August 2026 Patch Tuesday updates, is a remote code execution issue. It allows an attacker with low-level access to execute arbitrary code on an affected server without any user interaction. This was highlighted in Microsoft’s advisory, which categorized the flaw as a critical code injection vulnerability.

On September 25, 2026, Microsoft confirmed that they had observed real-world exploitation of CVE-2026-65660. Consequently, the Cybersecurity and Infrastructure Security Agency (CISA) included this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by September 28.

Evidence of Exploitation

Previdian, an early-warning threat intelligence platform formerly known as KEVIntel, reported seeing exploitation attempts as early as September 24. By the following day, there were attempts to install a webshell backdoor, indicating the severity of the threat.

The identity of the attackers remains unknown, but the attacks commenced shortly after Viettel Security, which initially reported the flaw to Microsoft, disclosed technical details. Initially, Microsoft classified the flaw as a medium-severity spoofing issue before elevating it to a high-severity remote code execution vulnerability.

Understanding the Vulnerability’s Impact

This vulnerability is considered an authenticated flaw, requiring attackers to have low-level privileges but not needing user interaction. Alone, it functions as a type-check bypass that can be leveraged for code execution by an authenticated attacker. However, to achieve unauthenticated remote code execution, it must be combined with another authentication bypass vulnerability.

Previdian noted that the observed exploits appear to be informed by the technical information released by Viettel. CISA’s KEV catalog now lists 16 SharePoint vulnerabilities, with eight discovered and patched in the current year.

The urgency of patching this vulnerability is underscored by the speed and sophistication of its exploitation in the wild, emphasizing the critical need for organizations to implement Microsoft’s security updates promptly.

Security Week News Tags:CISA, CVE-2026-65660, Cybersecurity, Microsoft, patch updates, Previdian, remote code execution, SharePoint, Viettel Security, Vulnerability

Post navigation

Previous Post: Unpatched Citrix NetScaler Flaws Pose Security Threat

Related Posts

Cisco Patches Vulnerability Exploited by Chinese Hackers Cisco Patches Vulnerability Exploited by Chinese Hackers Security Week News
Ransomware Payments Dropped in Q3 2025: Analysis Ransomware Payments Dropped in Q3 2025: Analysis Security Week News
Pakistan-Linked Cyber Espionage Targets India’s Defense Pakistan-Linked Cyber Espionage Targets India’s Defense Security Week News
Nevada Ransomware Attack Started Months Before It Was Discovered, Per Report Nevada Ransomware Attack Started Months Before It Was Discovered, Per Report Security Week News
Cybersecurity Leaders Request Easing of AI Model Restrictions Cybersecurity Leaders Request Easing of AI Model Restrictions Security Week News
Hackers Targeting Cisco Unified CM Zero-Day  Hackers Targeting Cisco Unified CM Zero-Day  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft SharePoint Vulnerability CVE-2026-65660 Under Attack
  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark