SharePoint flaw CVE-2026-65660 being actively exploited

A SharePoint vulnerability patched in August, CVE-2026-65660, is being exploited after technical details were posted; webshells and attack attempts were observed Sept. 24–25.

Security firms and U.S. agencies report active exploitation of a SharePoint vulnerability Microsoft patched in August. Observers recorded attack attempts on Sept. 24 and activity to deploy a webshell backdoor on Sept. 25 following publication of technical details about the flaw.

Microsoft resolved the issue as part of its August Patch Tuesday updates and described the bug as a code injection problem that can produce remote code execution. The company’s advisory characterizes the vulnerability as an authenticated type-check bypass that allows an attacker with low-level access to run arbitrary code on an affected SharePoint server without any other user interaction. Achieving unauthenticated remote code execution would require chaining this flaw with a separate authentication bypass.

Early-warning threat platform Previdian reported the exploitation attempts and the webshell activity after researchers who originally notified Microsoft published technical details. Microsoft updated its advisory on Sept. 25 to note it had reliable evidence of observed attacks against the vulnerability.

The Cybersecurity and Infrastructure Security Agency added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on Sept. 25 and set a federal patching deadline of Sept. 28. CISA’s catalog now lists 16 SharePoint vulnerabilities, eight of which were discovered and patched this year.

Microsoft initially assessed the bug as a medium-severity spoofing issue and later revised the rating to high severity for remote code execution after further analysis. Observers said the active exploits appear to track the technical information that was publicly posted.

Administrators who have not applied Microsoft’s August updates remain exposed to the vulnerability on affected servers. Reports indicate that, on its own, the flaw requires an authenticated account with low-level privileges to enable code execution; additional weaknesses would be needed to achieve unauthenticated access.

Articles by this author