Advertisement

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Summary: CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

A recently patched vulnerability in Microsoft SharePoint is now being actively exploited, prompting new warnings for organizations running vulnerable on-premises installations.

Tracked as CVE-2026-65660, the security flaw affects Microsoft SharePoint Server and can allow an authenticated attacker to execute code remotely under certain conditions. Microsoft addressed the vulnerability as part of its September 2026 security updates, but evidence of exploitation has since pushed the issue into a higher-priority category for defenders.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming that it is being used in real-world attacks.

Advertisement
SharePoint Servers Become High-Value Targets

SharePoint occupies a particularly sensitive position inside many enterprise environments.

Organizations use the platform to store documents, manage internal collaboration, host business information, and integrate with other Microsoft services. An attacker who compromises a SharePoint server may therefore gain access to significantly more than a conventional public-facing website.

CVE-2026-65660 is an improper input validation vulnerability that can result in remote code execution.

Exploitation requires authentication, meaning an attacker generally needs valid credentials before targeting the flaw. That requirement reduces exposure compared with a completely unauthenticated vulnerability, but it does not eliminate the threat.

Credential theft, phishing, infostealers, compromised accounts, and previous intrusions routinely provide attackers with legitimate enterprise identities.

Once an attacker has authenticated access, a vulnerability capable of turning that foothold into code execution becomes considerably more valuable.

CISA Confirms Active Exploitation

The addition of CVE-2026-65660 to CISA’s KEV catalog is particularly important because inclusion means there is evidence of exploitation outside theoretical laboratory testing.

CISA has not publicly disclosed detailed information about the attacks, including who is exploiting the vulnerability or which organizations are being targeted.

The agency’s warning nevertheless provides defenders with an important prioritization signal.

Thousands of vulnerabilities are disclosed every year, making it impossible for most organizations to remediate everything simultaneously. Confirmation that attackers are actively exploiting a particular flaw changes that calculation.

Organizations running affected SharePoint environments should treat CVE-2026-65660 as an immediate remediation priority.

On-Premises SharePoint Is the Main Concern

The vulnerability affects supported SharePoint Server products rather than Microsoft’s cloud-hosted SharePoint Online service.

This distinction matters because organizations running SharePoint on premises are responsible for deploying Microsoft’s security updates themselves.

Cloud services can often be patched centrally by the provider. Enterprise servers, by contrast, may remain exposed until administrators test, approve, and install the relevant update.

Legacy or poorly inventoried SharePoint installations can create additional problems.

An organization may have older collaboration servers that remain accessible even though they are no longer considered strategically important. Attackers routinely search for precisely these forgotten internet-facing systems because they may receive less monitoring and slower patching than newer infrastructure.

Authentication Requirements Do Not Make It Safe

The authenticated nature of CVE-2026-65660 illustrates an important vulnerability-management problem.

Organizations sometimes prioritize vulnerabilities almost exclusively according to whether they can be exploited anonymously from the internet.

But modern attacks frequently occur as chains.

An attacker may first obtain an employee’s credentials through phishing or an infostealer. Those credentials provide basic access to the organization but limited privileges.

The attacker can then exploit an authenticated vulnerability to move from:

Valid account → SharePoint access → Code execution → Deeper network compromise

The vulnerability therefore acts as a privilege and capability multiplier.

This is particularly dangerous when SharePoint servers have access to internal databases, authentication infrastructure, network shares, or other enterprise resources.

Patching Should Be Accompanied by Investigation

Organizations running affected SharePoint versions should install Microsoft’s September security updates or later patches containing the fix.

However, because exploitation has already been confirmed, organizations that operated vulnerable servers should not assume that patching alone resolves the problem.

Security teams should also review SharePoint and web server logs for suspicious activity, investigate unexpected processes or files associated with the SharePoint environment, examine unusual authentication events, and search for evidence of persistence.

If exploitation occurred before the server was patched, attackers may have established another method of maintaining access.

The security update closes CVE-2026-65660. It does not necessarily remove anything an attacker installed before remediation.

SharePoint Remains an Attractive Enterprise Attack Surface

Microsoft collaboration infrastructure has repeatedly attracted sophisticated attackers because these systems combine valuable information with privileged access to enterprise environments.

SharePoint servers are particularly interesting because they frequently sit at the intersection of users, documents, authentication, databases, and internal applications.

A compromised SharePoint server can therefore provide both sensitive information and a useful position for subsequent movement through the network.

CVE-2026-65660 reinforces a familiar lesson for defenders: vulnerability severity cannot be evaluated solely through a CVSS score or whether authentication is required.

Once attackers begin exploiting a vulnerability in real environments,exploitation evidence becomes one of the strongest signals for remediation priority.

Organizations operating on-premises SharePoint should identify affected servers, apply Microsoft’s security updates, and investigate systems that remained exposed during the period when CVE-2026-65660 was vulnerable to attack.

Advertisement

Key facts

  • Microsoft SharePoint flaw identified as CVE-2026-65660 is now being exploited
  • CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities (KEV) catalog
  • Federal agencies are given a patching deadline of September 28 for this vulnerability

Why it matters

The inclusion of CVE-2026-65660 in CISA's KEV catalog signifies that this Microsoft SharePoint vulnerability is no longer a theoretical threat but is actively being weaponized by malicious actors. The mandated September 28 patching deadline for federal agencies underscores the urgency and potential impact on government systems, serving as a critical alert for all organizations using SharePoint to prioritize remediation efforts and bolster their defenses against active exploitation.