Code Injection Vulnerability in Microsoft Office SharePoint
CVE-2026-65660

8.8HIGH

Key Information:

Badges

🔥 Trending now📈 Trended📈 Score: 6,740👾 Exploit Exists🟡 Public PoC🦅 CISA Reported📰 News Worthy

What is CVE-2026-65660?

CVE-2026-65660 is a vulnerability identified in Microsoft Office SharePoint, a widely used platform that facilitates collaboration and document management within organizations. This vulnerability stems from improper control over the generation of code, known as a code injection issue. An authorized attacker could exploit this flaw to execute arbitrary code over a network. The implications of such an exploit are significant, as it could lead to unauthorized access to sensitive information, system manipulation, or the introduction of malicious actions within the SharePoint environment. Given the critical nature of the data often managed within SharePoint, this vulnerability can pose serious risks to organizational integrity, confidentiality, and availability of resources.

Potential impact of CVE-2026-65660

  1. Unauthorized Code Execution: This vulnerability enables an attacker to execute arbitrary code on the affected systems. If exploited, this can lead to unauthorized control over the SharePoint environment, allowing for the deployment of malicious software or other harmful actions.

  2. Data Breaches: Exploitation of this vulnerability may result in unauthorized access to sensitive organizational data stored within SharePoint. This can lead to data leaks, theft, or manipulation of critical information, undermining data integrity and confidentiality.

  3. Disruption of Services: With the ability to execute arbitrary code, attackers can disrupt normal operations within SharePoint, potentially causing downtime, service interruptions, or loss of access to crucial applications that rely on the platform, significantly impacting business continuity.

CISA has reported CVE-2026-65660

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-65660 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5565.1001

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10417.20198

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.19725.20522

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild - SwapUpdate

Ravie LakshmananSep 26, 2026Vulnerability / Network Security

2 days ago

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Microsoft confirmed active exploitation of SharePoint flaw CVE-2026-65660, prompting CISA to add the RCE bug to its KEV list.

2 days ago

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

CISA adds exploited SharePoint RCE and RouterOS flaws to KEV; the RouterOS chain can give unauthenticated administrative access.

3 days ago

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 🦅

    CISA Reported

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.