SharePoint CVE-2026-65660 Called Authenticated RCE, Now Exploited
Canada reports active exploitation of SharePoint CVE-2026-65660, an authenticated RCE Microsoft first listed as spoofing and patched August 11.
CVE-2026-65660 is a code-injection flaw (CWE-94) in on-premises Microsoft SharePoint Server 2016, 2019, and Subscription Edition that lets a low-privileged authenticated attacker run arbitrary code over the network without user interaction. Sources disagree on severity: The Hacker News says Microsoft's advisory first called it spoofing scored 6.5, while NVD and Cyber Security News list it as CVSS 8.8 code injection, and Cyber Security News adds that unsupported SharePoint 2013 is affected but will not be patched. Viettel Cyber Security researcher Dinh Ho Anh Khoa described a SafeControls bypass in ToolPane handling that can lead to in-memory code execution; public write-ups include exploit details, which are omitted here. Microsoft released fixes on August 11, 2026—builds 16.0.5565.1001 (2016), 16.0.10417.20198 (2019), and 16.0.19725.20522 (Subscription Edition)—and those updates disable the vulnerable function by default. The Hacker News, Cyber Security News, and GBHackers said the flaw was not known to be exploited and was not in CISA's KEV catalog, but on September 24 Canada's Cyber Centre (AL26-023) said it is being actively exploited. Canada also said chaining with other SharePoint bugs can yield pre-authentication RCE where anonymous access is allowed—The Hacker News identifies a separate bypass, CVE-2026-55040, fixed June 9—and urged patching or migration off SharePoint 2016 and 2019, which reached end of life on July 15, 2026, plus MFA, AMSI Full Mode, and monitoring for web shells and suspicious IIS activity.
- CVE-2026-65660 (CWE-94) affects on-premises SharePoint Server 2016, 2019, and Subscription Edition; Cyber Security News says unsupported SharePoint 2013 is also affected and will not be patched.
- NVD and Cyber Security News score it CVSS 8.8 as code injection; The Hacker News says Microsoft first listed it as spoofing at 6.5.
- A low-privileged authenticated attacker can run arbitrary code over the network without user interaction via a SafeControls bypass in ToolPane handling, including in-memory code execution.
- Microsoft patched it on August 11, 2026, in builds 16.0.5565.1001 (2016), 16.0.10417.20198 (2019), and 16.0.19725.20522 (Subscription Edition); those updates also disable the vulnerable function by default.
- The Hacker News, Cyber Security News, and GBHackers said exploitation was not known and the flaw was not in CISA's KEV catalog; Canada's Cyber Centre alert AL26-023 (September 24, 2026) says it is actively exploited.
- Chaining with other SharePoint bugs, including authentication bypass CVE-2026-55040 fixed on June 9, can enable pre-authentication RCE where anonymous access is allowed.
- SharePoint Server 2016 and 2019 reached end of life on July 15, 2026; Canada urges patching or migration, MFA, AMSI Full Mode, and monitoring for web shells and suspicious IIS activity.
- Viettel Cyber Security researcher Dinh Ho Anh Khoa published the technical details; public research includes exploit markup, which is not reproduced here.
Coverage timelineoldest first · each row is one article
- · 4d agoSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
The Hacker News· 68
Researchers show SharePoint CVE-2026-65660 enables authenticated RCE, despite Microsoft first listing it as spoofing.
- · 4d agoMicrosoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges
Cyber Security News· 64
Microsoft patched CVE-2026-65660, an authenticated SharePoint Server remote code execution flaw scored 8.8.
- · 3d ago
Vulnerabilities in this storyAll →
- CVE-2026-550409.118%Authentication Bypass in Microsoft SharePoint Serverpublished · Microsoft SharePoint Server KEV PoC ×2