SharePoint flaw moves from spoofing label to actively exploited code execution

A Microsoft SharePoint Server vulnerability first handled as a spoofing issue is now an actively exploited code execution flaw.

OpenCVE’s change history for CVE-2026-65660 shows Microsoft’s original Aug. 11, 2026, description as an authorized attacker being able to perform spoofing over a network. The Aug. 27 update changed the title to Microsoft SharePoint Server Remote Code Execution Vulnerability, changed the description to code execution over a network, and raised the CVSS 3.1 score from 6.5 to 8.8.

Some security teams may have made their first patch decision from a lower-risk label that later changed. The underlying weakness classification, CWE-94 code injection, stayed central to the record. A network-reachable, low-privilege, no-user-interaction code injection flaw in SharePoint deserves attention even if an early advisory label sounds less severe.

Active exploitation changed the operational risk

CISA said on Sept. 25 that it added CVE-2026-65660 to the KEV catalog based on evidence of active exploitation. The agency set Sept. 28 as the remediation due date for affected federal civilian agencies. CISA’s current KEV guidance also points to forensic triage requirements, reinforcing that patch validation should be paired with evidence review where compromise is suspected.

The Canadian Centre for Cyber Security issued its own alert a day earlier, saying it was aware of active exploitation affecting Microsoft SharePoint Server.

The Canadian alert described the vulnerability as improper control of code generation, or code injection, affecting multiple SharePoint Server versions. It said an authenticated attacker could execute arbitrary code on vulnerable SharePoint servers. The agency also warned that, when chained with other SharePoint vulnerabilities, the flaw can achieve pre-authentication remote code execution on SharePoint servers configured to permit anonymous access.

Previdian, which published technical observations on Sept. 24, said its SharePoint honeypot captured 12 exploitation requests that day. That telemetry is not proof of a broad campaign by itself, but it supports the shift from theoretical risk to real-world probing.

Who is affected

The public records reviewed for this article identify on-premises SharePoint Server products, not SharePoint Online. The affected products and fixed versions listed by the Canadian Centre for Cyber Security are:

ProductAffected versionsFixed version
Microsoft SharePoint Enterprise Server 2016Versions before 16.0.5565.100116.0.5565.1001
Microsoft SharePoint Server 2019Versions before 16.0.10417.2019816.0.10417.20198
Microsoft SharePoint Server Subscription EditionVersions before 16.0.19725.2052216.0.19725.20522

Microsoft’s SharePoint update history also lists the Aug. 11 updates for those product lines. For SharePoint Server 2019, Microsoft lists KB5002894 and KB5002896 at version 16.0.10417.20198. For SharePoint Server 2016, Microsoft lists KB5002905 and KB5002906 at version 16.0.5565.1001. For Subscription Edition, Microsoft lists KB5002893 at version 16.0.19725.20522, followed by a newer September update.

The Canadian Cyber Centre also noted that SharePoint Enterprise Server 2016 and SharePoint Server 2019 reached end of life on July 15, 2026, and urged migration to a supported version. That makes the issue larger than a single CVE for organizations still relying on those farms.

The authentication detail is easy to misread

CVE-2026-65660 by itself is an authenticated vulnerability. The Microsoft-supplied CVSS vector uses low privileges required and no user interaction, which means an attacker needs some level of authorized access but does not need a user to click or open anything during exploitation.

The pre-authentication risk comes from chaining. Previdian’s write-up said the observed traffic combined the CVE-2026-65660 quote-injection body with a separate anonymous delivery path affecting sites configured to allow anonymous viewing. According to Previdian’s account of Viettel Cyber Security’s research, that anonymous delivery issue was fixed on June 9, 2026, while CVE-2026-65660 was fixed on Aug. 11.

The distinction matters. A fully updated SharePoint deployment should have both parts of that reported chain closed. A server missing prior SharePoint updates, exposing SharePoint directly to the internet, or permitting anonymous access may carry more risk than a CVE scanner summary suggests.

What administrators should review now

For affected environments, the response should include patch validation and evidence review. CISA’s bulletin points federal agencies to risk-based remediation requirements under Binding Operational Directive 26-04, while also encouraging other organizations to prioritize KEV-listed vulnerabilities.

  • Confirm every SharePoint farm, including test and legacy environments, is at or beyond the fixed build for its product line.
  • Apply the latest relevant SharePoint security updates, not only the update associated with a single CVE, since SharePoint updates are cumulative and farms can require both language-independent and language-dependent packages.
  • Review direct internet exposure, access to SharePoint Central Administration, and any site configuration that permits anonymous viewing.
  • Hunt SharePoint, IIS, endpoint, and authentication logs for suspicious authenticated access, unexpected web part changes, unusual administrative actions, attempts to access IIS machine keys, deserialization activity, web shell deployment, or malicious process execution.
  • Where operationally feasible, enable SharePoint Antimalware Scan Interface integration and Full Mode request-body scanning as an added detection layer, not as a replacement for patching.
  • For SharePoint Server 2016 and 2019, treat migration planning as part of the security response because both products are now outside normal support.

Previdian’s observed requests centered on POST traffic to AddGallery.aspx and designgallery.aspx paths with edit-mode behavior. That does not prove every similar request is malicious, but it gives defenders a useful place to begin log review when paired with timestamps, source reputation, authentication context, and follow-on server activity.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email