A Critical Microsoft SharePoint Vulnerability is Now Being Exploited in Real-World Attacks
In a disturbing turn of events, a previously patched vulnerability in Microsoft’s popular collaboration platform, SharePoint, has been exploited by attackers. CVE-2026-65660, a remote code execution flaw that was fixed by Microsoft in August, is now being actively targeted by malicious actors.
The vulnerability allows an authenticated attacker with low-level access to execute arbitrary code on an affected server without requiring user interaction. According to Microsoft’s updated advisory, the company has reliable evidence of observed attacks against exploitation of this vulnerability. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25, giving federal agencies a patching deadline of September 28.
The attackers appear to have started exploiting the vulnerability shortly after Viettel Security, whose researchers reported it to Microsoft, disclosed technical details. It’s unclear who is behind these attacks, but experts suspect that they may be linked to the same malicious groups responsible for other recent high-profile breaches.
CVE-2026-65660 is a type-check bypass that can be exploited by an attacker with low-level privileges. To reach unauthenticated remote code execution, it requires chaining with another authentication bypass weakness. Previdian, a threat intelligence platform, reported seeing exploitation attempts on September 24 and attempted webshell backdoor creation the following day.
The fact that attackers have already begun exploiting this vulnerability highlights the importance of keeping software up to date. Microsoft initially rated CVE-2026-65660 as a medium-severity spoofing issue but later revised its assessment to high-severity remote code execution flaw after further analysis.
CISA’s KEV catalog currently lists 16 SharePoint vulnerabilities, including eight discovered and patched this year. This vulnerability is a stark reminder that even previously patched flaws can be exploited by determined attackers. It also underscores the need for organizations to prioritize patching and keep their systems up to date to prevent potential breaches.
To protect against exploitation of CVE-2026-65660, it’s essential to apply the August 2026 Patch Tuesday updates and ensure that all dependencies are updated as well. Additionally, consider implementing robust threat detection and response measures to quickly identify and contain any potential attacks.
Source: SecurityWeek — 2026-09-27