Code Injection Vulnerability in Microsoft Office SharePoint
CVE-2026-65660
6.5MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-65660?
A vulnerability in Microsoft Office SharePoint permits an authorized attacker to execute code injection, enabling them to perform spoofing attacks over a network. This weakness poses significant risks as it can lead to unauthorized access and manipulation of sensitive information. Organizations utilizing affected versions of SharePoint should implement the recommended patches to mitigate these risks and enhance their overall security posture.
Affected Version(s)
Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5565.1001
Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20198
Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20522