News Date: 2026-09-27
A Microsoft SharePoint Server vulnerability originally addressed in August has entered active exploitation, placing organizations with delayed patch cycles under immediate pressure. Tracked as CVE-2026-65660, the weakness allows an authenticated attacker with relatively low-level access to execute arbitrary code on an affected server.
Why the vulnerability matters
SharePoint often contains business documents, internal communications and workflow data, while also maintaining trusted connections to identity systems, databases and other Microsoft services. Code execution on the server can therefore become more than a single-application compromise. It may provide access to credentials, configuration files and systems reachable through the SharePoint host.
The vulnerability involves a type-check bypass that results in code injection. Microsoft initially described it as a spoofing issue but later revised the assessment to a high-severity remote code execution vulnerability. Exploitation requires an authenticated account with low privileges when the flaw is used alone. An attacker would need to combine it with a separate authentication bypass to achieve an unauthenticated attack chain.
Microsoft confirmed reliable evidence of observed attacks on September 25. Threat-intelligence monitoring also detected exploitation attempts and activity intended to create web-shell backdoors shortly after technical details became public.
The remediation clock is already running
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog and instructed US federal civilian agencies to complete remediation by September 28. Private-sector organizations are not legally bound by that deadline, but the catalog entry provides strong evidence that ordinary patch scheduling is no longer appropriate.
Recommended actions
- Install the relevant August 2026 SharePoint security updates immediately.
- Inventory every on-premises SharePoint server, including test and recovery systems.
- Review IIS, SharePoint and endpoint logs for suspicious requests or process execution.
- Search web directories for recently created scripts, assemblies and web shells.
- Rotate service credentials and secrets if compromise is suspected.
- Restrict administrative and user access to SharePoint from untrusted networks.
In my view, the key lesson is that authenticated vulnerabilities should not be treated as low priority. Stolen credentials are widely available, and a basic user account can be easier to obtain than a sophisticated zero-day. Once exploit details become public, the difference between a patched collaboration server and an exposed one can be measured in hours rather than weeks.
