Select a theme from the list.
Insights

From our experts

Latest
SharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack Playbook
Security Insight

SharePoint Code-Execution Flaw Moves From Patch Notes to Active Attacks

SharePoint Code-Execution Flaw Moves From Patch Notes to Active Attacks
Photo by Ann H on Pexels

Attackers are exploiting CVE-2026-65660, a SharePoint Server code-injection vulnerability corrected in Microsoft's August 2026 updates. The flaw allows an authenticated user with limited privileges to execute code without requiring further user interaction. CISA has added the vulnerability to its exploited-flaws catalog and set a September 28 remediation deadline for US federal agencies.

News Date: 2026-09-27

A Microsoft SharePoint Server vulnerability originally addressed in August has entered active exploitation, placing organizations with delayed patch cycles under immediate pressure. Tracked as CVE-2026-65660, the weakness allows an authenticated attacker with relatively low-level access to execute arbitrary code on an affected server.

Why the vulnerability matters

SharePoint often contains business documents, internal communications and workflow data, while also maintaining trusted connections to identity systems, databases and other Microsoft services. Code execution on the server can therefore become more than a single-application compromise. It may provide access to credentials, configuration files and systems reachable through the SharePoint host.

The vulnerability involves a type-check bypass that results in code injection. Microsoft initially described it as a spoofing issue but later revised the assessment to a high-severity remote code execution vulnerability. Exploitation requires an authenticated account with low privileges when the flaw is used alone. An attacker would need to combine it with a separate authentication bypass to achieve an unauthenticated attack chain.

Microsoft confirmed reliable evidence of observed attacks on September 25. Threat-intelligence monitoring also detected exploitation attempts and activity intended to create web-shell backdoors shortly after technical details became public.

The remediation clock is already running

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog and instructed US federal civilian agencies to complete remediation by September 28. Private-sector organizations are not legally bound by that deadline, but the catalog entry provides strong evidence that ordinary patch scheduling is no longer appropriate.

Recommended actions

  • Install the relevant August 2026 SharePoint security updates immediately.
  • Inventory every on-premises SharePoint server, including test and recovery systems.
  • Review IIS, SharePoint and endpoint logs for suspicious requests or process execution.
  • Search web directories for recently created scripts, assemblies and web shells.
  • Rotate service credentials and secrets if compromise is suspected.
  • Restrict administrative and user access to SharePoint from untrusted networks.

In my view, the key lesson is that authenticated vulnerabilities should not be treated as low priority. Stolen credentials are widely available, and a basic user account can be easier to obtain than a sophisticated zero-day. Once exploit details become public, the difference between a patched collaboration server and an exposed one can be measured in hours rather than weeks.

Talk to our team →

Latest

SharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksSep 28, 2026Lunex Leaves Security Tools Running but Blind Before Raiding BrowsersSep 28, 2026Cloudflare Container Flaw Broke the Wall Between Customer WorkloadsSep 28, 2026Storm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutSep 27, 2026One Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftSep 27, 2026Clop Ransomware Gang Gets Hacked Through Its Own Outdated CMSSep 27, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards