SharePoint CVE-2026-65660 Was Patched as Spoofing, Then Exploited as Code Execution
Security / news
SharePoint CVE-2026-65660 Was Patched as Spoofing, Then Exploited as Code Execution
Microsoft's August fix carried a 6.5 rating; by Sept. 25 CISA had it in the exploited catalog at 8.8, with a three-day deadline.

An attacker with a low-privilege SharePoint account can run arbitrary code on the server through CVE-2026-65660, no user interaction needed, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on Sept. 25. Federal agencies had until Sept. 28 to patch. The fix has been available since Aug. 11.
Microsoft first labelled the bug a spoofing issue. Previdian, the threat-intelligence service formerly called KEVIntel, records the original rating as CVSS 6.5. The current rating is 8.8, and the weakness class is code injection (CWE-94). SecurityWeek credits the discovery to Viettel Security researchers and says exploitation appeared after Viettel published technical details in September.

What an attacker needs
The flaw is authenticated. SecurityWeek describes it as a code injection issue that lets an attacker with low-level access to an affected server execute arbitrary code, and says a fully unauthenticated attack would need a separate authentication bypass chained in front of it. Neither source reports that chain in use.
The score overstates the risk for a SharePoint farm where only vetted staff hold accounts, and understates it for one that hands accounts to contractors, partners or self-service tenants. Read the 8.8 as "any account", not "any visitor".
Affected builds and the fix
Patches shipped on Aug. 11 with Microsoft's monthly cycle. Previdian lists three products and the first fixed build of each.
| Product | Fixed in build |
|---|---|
| SharePoint Enterprise Server 2016 | 16.0.5565.1001 |
| SharePoint Server 2019 | 16.0.10417.20198 |
| SharePoint Server Subscription Edition | 16.0.19725.20522 |
Operators who applied the August update are covered. The exposure is farms that skipped it because a 6.5 spoofing rating looked ordinary.
How much exploitation there is
Previdian saw the first attempts on Sept. 24 and the last on Sept. 28. On Sept. 25 it recorded attempts to create a webshell backdoor. Its totals are small: 18 attempts from 4 unique attacker IP addresses in 3 countries (the United Kingdom, Israel and the United States), all recorded by 1 honeypot sensor.
That is one sensor's view and says little about how many real servers were hit. Previdian also lists the exploit prediction score (EPSS) at 2.1%, a low probability figure for a flaw that CISA has already marked as exploited.
- Exploitation attempts18 count
- Unique attacker IPs4 count
- Attacker countries3 count
- Honeypot sensors1 count
Source: Previdian, accessed 2026-09-29
Timeline
- Aug. 11: Microsoft ships the fix, rated as a 6.5 spoofing issue.
- September: Viettel Security publishes technical details and proof-of-concept code, per SecurityWeek.
- Sept. 24: Previdian records the first exploitation attempts.
- Sept. 25: CISA lists the flaw with a Sept. 28 deadline.
Microsoft's September release was a record 966-fix Patch Tuesday with two exploited bugs, both local. This August fix was not among them, which is the argument for tracking the exploited catalog alongside the monthly release. Another exploited flaw on the same list of edge-of-network products is F5's BIG-IP APM zero-day.
The practical instruction is to confirm the build number against the table above. Previdian's page carries no webshell details, and SecurityWeek's article does not give the date Microsoft changed the classification.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.