Microsoft's SharePoint 'Spoofing' Bug Is Really an RCE Flaw
Security / news
Microsoft's SharePoint 'Spoofing' Bug Is Really an RCE Flaw
CVE-2026-65660 sat rated 6.5 for weeks until a Viettel researcher showed it grants remote code execution, and CISA added it to its exploited-vulnerabilities catalog Sept. 25 after attackers began installing webshells.

An authenticated attacker with only low-level access to a SharePoint Server can execute code remotely by chaining a markup-injection bug with a page that allows anonymous viewing, according to a technical writeup a Viettel Cyber Security researcher published before Microsoft's own severity rating caught up. The Cybersecurity and Infrastructure Security Agency added the flaw, CVE-2026-65660, to its exploited-vulnerabilities catalog on Sept. 25, giving federal civilian agencies until Sept. 28 to patch.
Microsoft patched CVE-2026-65660 quietly on Aug. 11 in its regular monthly release, rating it 6.5 and classifying it only as a spoofing issue with no impact on data integrity or availability, The Hacker News reported Sept. 22, citing Microsoft's own advisory text.
That rating did not survive contact with Dinh Ho Anh Khoa's own analysis. The Viettel Cyber Security researcher, who demonstrated the original ToolShell exploit chain against SharePoint at Pwn2Own Berlin in May 2025, published technical details showing the bug lets an attacker register classes outside SharePoint's SafeControls allowlist and trigger deserialization through XamlServices.Parse(), The Hacker News and SecurityWeek both reported.
How the bypass actually works
"The logic is simple, just append the attribute value to a format without any check," Khoa wrote, describing how SharePoint's ToolPane component fails to escape double-quote characters in web-part markup, according to a technical summary published by Security Online. An attacker who can inject a quote into a directive attribute clears the SafeControls check outright.
From there, the exploit reaches Microsoft's own XamlServices parser through a chain of two .NET gadget classes, ObjectDataProvider and ExpandedWrapper, and hands it a LosFormatter-encoded payload to deserialize in memory. Nothing touches disk; the webshell that results runs under whatever account SharePoint's own service uses. Attackers pick pages such as AddGallery.aspx, which permit anonymous viewing, so the chain fires without ever authenticating, according to Security Online's account.
A rating that took five weeks to catch up
| Date | Event |
|---|---|
| Aug. 11 | Microsoft patches CVE-2026-65660, rates it 6.5, calls it spoofing |
| Sept. 11 | Microsoft's own CVE record is revised to remote code execution |
| Sept. 22 | Khoa's technical writeup is published; no exploitation reported yet |
| Sept. 24 | Previdian observes exploitation attempts begin |
| Sept. 25 | Webshell deployment observed; CISA adds the flaw to KEV at CVSS 8.8 |
Microsoft's own CVE record was revised to correctly describe the flaw as remote code execution on Sept. 11, more than three weeks after the original patch and 11 days before The Hacker News's report on Khoa's writeup, though the Aug. 11 fix was already sufficient against it. The score's slow climb, from 6.5 to 8.8, tracked the public understanding of the bug rather than any change in the bug itself, a pattern this site has flagged before in a Chrome zero-day whose own precondition mattered more than its number.
Who is watching, and what isn't known yet
Previdian, the threat-intelligence firm formerly known as KEVIntel, reported seeing exploitation attempts on Sept. 24, SecurityWeek said. Activity to deploy a webshell backdoor followed the next day, the same day CISA's catalog addition set the Sept. 28 deadline.
Neither SecurityWeek nor The Hacker News names the attackers or says how many servers have been compromised, a gap consistent with how CISA's own catalog additions read this September. SharePoint Online is not affected; the flaw is confined to on-premises Server 2016, 2019 and Subscription Edition builds, patched respectively at versions 16.0.5565.1001, 16.0.10417.20198 and 16.0.19725.20522.
Any SharePoint Server still running an older build remains vulnerable regardless of the KEV listing. CISA's Sept. 28 deadline binds only federal civilian agencies, not the banks, universities and enterprises that make up most of SharePoint's on-premises install base.
Sources
- Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks, SecurityWeek
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE, The Hacker News
- CVE-2026-65660: Microsoft SharePoint RCE Exploit, Technical Breakdown, The CyberSec Guru
- Exploited SharePoint RCE Vulnerability Details Disclosed, Security Online
Sources
More in Security
- 01Siemens' Edge Platform Still Carried a Keycloak Bug Fixed in AugustCISA published the advisory on Sept. 22, more than a month after Red Hat shipped the upstream fix, because four Siemens Industrial Edge Management products bundle the identity server.
- 02LuaRocks Patches a Bytecode Flaw Attackers Used for Six WeeksAn independent researcher's writeup, published a day after the fix, names the LuaJIT instruction that let a crafted package listing read and write server memory.
- 03Graphalgo Malware Reaches Terraform Providers for the First TimeTwo fake Terraform providers and two Go modules polled an Ethereum contract every 3 seconds as a backup channel, security firm Aikido said, describing the campaign's first use of HashiCorp's registry.
- 04CISA's WSO2 Catalog Entry Names the Wrong VulnerabilityThe agency's Sept. 24 addition of CVE-2026-5430 borrows language from a different, four-year-old WSO2 flaw, even as watchTowr reports live attacks forging admin tokens through the real one.