MikhbarMIKHBAR
Cybersecurity

Microsoft SharePoint Flaw CVE-2026-65660 Active Attacks

A high-severity remote code execution vulnerability in Microsoft SharePoint is now being actively targeted in real-world attacks, roughly six weeks after the initial patches were released.

Microsoft SharePoint Flaw CVE-2026-65660 Active Attacks

Overview of SharePoint Vulnerability CVE-2026-65660

A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is now actively exploited in the wild. The remote code execution vulnerability was initially fixed by Microsoft as part of its August 2026 Patch Tuesday updates. According to the company's official advisory, the bug involves a code injection issue allowing an authenticated attacker with low-level server access to execute arbitrary code without requiring user interaction.

Microsoft updated its security guidance after confirming reliable evidence of observed exploitation attempts against the vulnerability. The security issue functions as a type-check bypass that provides code execution to authenticated attackers, though achieving unauthenticated remote code execution requires chaining it with a separate authentication bypass weakness.

Detection and Early Threat Intelligence Observations

Early-warning threat intelligence platforms began tracking suspicious activity shortly after technical details became public. Previdian, formerly known as KEVIntel, reported observing exploitation attempts targeting servers on September 24. By September 25, the platform recorded explicit attempts to create a webshell backdoor on affected instances.

Security analysts noted that the active exploitation attempts observed in the wild appear closely aligned with the public technical disclosures. While the exact threat actors behind the campaign remain unidentified, the surge in activity closely followed technical write-ups released by cybersecurity researchers.

CISA Response and Federal Patching Deadlines

In response to the confirmed active exploitation, the Cybersecurity and Infrastructure Security Agency intervened swiftly. CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog, setting a mandatory patching deadline for federal civilian executive branch agencies.

The federal directive ordered agencies to complete remediation steps by September 28. This addition increases the total number of SharePoint vulnerabilities listed in CISA's catalog, highlighting the platform's ongoing appeal as a target for malicious actors.

Severity Reassessment and Research Discovery

Researchers at Viettel Security originally discovered the flaw and reported it to Microsoft. According to Viettel, Microsoft initially categorized the issue as a medium-severity spoofing problem before revising the assessment to a high-severity remote code execution flaw.

The transition in severity rating underscores the complex nature of modern enterprise software vulnerabilities. Organizations utilizing Microsoft SharePoint are strongly encouraged to verify that all applicable patches from the August security release are fully deployed across their infrastructure to mitigate potential remote code execution risks.

Sources

  • SecurityWeekMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks