Global technology recovery · 2026-09-25
SharePoint CVE-2026-65660 is under active exploitation; agencies are telling on-premises operators to install Microsoft’s August fixes today.
Key takeaways
- On-premises Microsoft SharePoint Server
- Authenticated remote code execution
- 28 September 2026 for US federal agencies
Microsoft SharePoint CVE-2026-65660 is being exploited in attacks, prompting CISA to place the on-premises SharePoint Server flaw in its Known Exploited Vulnerabilities catalog with a 28 September deadline for US federal agencies. Microsoft fixed the code-injection vulnerability in its August 2026 security updates.
The flaw allows a low-privileged authenticated attacker to execute code over a network without user interaction. That means it is not a fully unauthenticated entry point, but organisations should not treat authentication as a sufficient control: stolen or weak accounts can supply the foothold.
What SharePoint CVE-2026-65660 changes
Microsoft’s advisory now says it has reliable evidence of observed attacks. CISA’s KEV addition converts that evidence into an operational deadline for federal systems, while Canada’s Cyber Centre has separately warned administrators about active exploitation.
The affected surface is on-premises SharePoint Server, where administrators own patching and incident response. The reviewed advisories do not frame this as a SharePoint Online customer patch. Operators should verify product edition and build instead of assuming every service carrying the SharePoint name has the same exposure.
The urgency resembles CISA’s Linux kernel KEV deadline, but the remediation path is product-specific. A catalog entry confirms exploitation; it does not reveal every victim, threat actor or post-exploitation action.
Patch first, then look for compromise
Installing Microsoft’s August fixes closes the known code path, but patching alone cannot erase activity that happened earlier. Defenders should inventory every externally reachable SharePoint farm, confirm installed build levels and review Microsoft and national-agency detection guidance.
Teams should preserve relevant web, authentication and endpoint logs before rotating infrastructure or rebuilding servers. They should investigate unexpected application files, unusual child processes, new scheduled tasks and suspicious account use, while avoiding indicators copied from unrelated SharePoint campaigns unless current guidance supports them.
This sequence—patch, preserve evidence, hunt and rotate exposed secrets where justified—is more useful than a generic alert. Our coverage of Android’s September security update made the same distinction between a fixed vulnerability and a confirmed compromise.
Why the authenticated condition still matters
Authenticated flaws are sometimes deprioritised because they require an account. In enterprise collaboration systems, however, large user populations, contractors, legacy credentials and phishing make a low-privileged identity a realistic starting point. Once code executes on a SharePoint server, the attacker may reach sensitive documents or use the host as a bridge.
Administrators should therefore pair the update with tighter sign-in controls, least privilege and monitoring. Governance measures such as Microsoft’s school AI safety standard address policy at a higher layer; CVE-2026-65660 shows why foundational server hygiene remains non-negotiable.
The verified conclusion is narrow but urgent: active exploitation has been observed, Microsoft has patches, and agencies want affected on-premises servers updated immediately. Claims about actor identity, victim count or campaign scope remain outside this package because the reviewed primary records do not establish them.
Facts at a glance
| CVE | CVE-2026-65660 |
|---|---|
| Affected product | On-premises Microsoft SharePoint Server |
| Impact | Authenticated remote code execution |
| Microsoft fix | August 2026 security updates |
| CISA deadline | 28 September 2026 for US federal agencies |
Frequently asked questions
What is CVE-2026-65660?
It is a SharePoint Server code-injection flaw that can let a low-privileged authenticated attacker execute code over a network.
Is SharePoint Online affected?
The reviewed advisories focus on on-premises SharePoint Server; administrators should follow Microsoft’s product-specific guidance.
What should defenders do first?
Inventory on-premises SharePoint, install Microsoft’s August updates, then investigate for compromise using current vendor and agency guidance.
Recovery article using the event’s actual public-disclosure date. Claims and limits are recorded in the research ledger.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



