Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Microsoft SharePoint Flaw Now Exploited in Attacks, Highlighting Importance of Timely Patching

A critical vulnerability in Microsoft’s SharePoint platform, tracked as CVE-2026-65660, is being actively exploited by attackers. This remote code execution flaw was patched by Microsoft on August 10th, but it seems that some malicious actors have already found ways to take advantage of the weakness.

The issue arises when an authenticated attacker with low-level access to a SharePoint server can inject arbitrary code without requiring user interaction. This means that even if a user has not interacted with the system, they can still be affected by the attack. Microsoft initially classified the vulnerability as a medium-severity spoofing issue but later revised its assessment to a high-severity remote code execution flaw.

The exploitation of CVE-2026-65660 appears to have started shortly after Viettel Security, whose researchers reported the vulnerability to Microsoft, disclosed technical details about it. This highlights the importance of responsible disclosure practices and the need for vendors to quickly patch identified vulnerabilities.

Microsoft had already provided patches for this vulnerability as part of its August Patch Tuesday updates. However, despite these efforts, some organizations may still be vulnerable if they have not applied the necessary fixes or if their systems are not properly configured. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-65660 to its Known Exploitable Vulnerabilities (KEV) catalog, giving federal agencies a patching deadline of September 28th.

Early-warning threat intelligence platform Previdian reported seeing exploitation attempts on September 24th. Just the next day, the company observed attempts to create a webshell backdoor, which is often used by attackers to gain unauthorized access to systems. The fact that these attacks are happening so soon after the vulnerability was disclosed suggests that malicious actors may have already been preparing for this moment.

The exploitation of CVE-2026-65660 serves as a reminder of the importance of timely patching and proper system configuration. Organizations should ensure they apply all available security updates to prevent such attacks from succeeding. This is especially crucial for critical systems, which can have far-reaching consequences if compromised.


Source: SecurityWeek — 2026-09-27