AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
Canada’s Cyber Centre says SharePoint flaw CVE-2026-65660 is actively exploited for code execution.
The Canadian Centre for Cyber Security alert AL26-023 says CVE-2026-65660, a code-injection flaw (CWE-94) in Microsoft SharePoint Server, is being actively exploited. An authenticated attacker can execute arbitrary code, and chaining it with other SharePoint bugs can yield pre-authentication remote code execution where anonymous access is allowed. Fixed versions are 16.0.5565.1001 for Server 2016, 16.0.10417.20198 for Server 2019, and 16.0.19725.20522 for Subscription Edition. SharePoint 2016 and 2019 reached end of life on July 15, 2026; the centre urges patching, migration, MFA, AMSI Full Mode, and monitoring for web shells and suspicious IIS activity.
- CVE-2026-65660 is code injection in on-premises SharePoint.
- Active exploitation is reported; chaining can enable pre-auth RCE.
- Fixed builds are listed for 2016, 2019, and Subscription Edition.
- SharePoint 2016 and 2019 went end of life on July 15, 2026.
Coverage timelineoldest first · each row is one article
- · 6d agoAL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
Canadian Centre for Cyber Security· 86
Canada’s Cyber Centre says SharePoint flaw CVE-2026-65660 is actively exploited for code execution.
- · 4d agoMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
SecurityWeek· 82
Attackers are exploiting patched Microsoft SharePoint flaw CVE-2026-65660, which CISA added to KEV.
- · 2d agoCISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks
Cyber Security News· 82
Vulnerabilities in this storyAll →
- CVE-2026-656608.82%Authenticated Code Injection RCE in Microsoft SharePoint Serverpublished · Microsoft SharePoint Server KEV PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure |
|---|