Skip to main content

Microsoft SharePoint Code Injection Flaw Exploited After Being Mislabeled as Low Risk for 45 Days (CVE-2026-65660)

Scope: Microsoft SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition (On-Premises Deployments)

Severity: Red

Microsoft originally patched CVE-2026-65660 on August 11, 2026 as part of its regular Patch Tuesday cycle, but classified it as a low-severity "spoofing" issue with a CVSS score of 6.5, giving organizations no strong signal to prioritize it. Security researchers later determined the flaw is actually a code injection vulnerability allowing an authenticated attacker with only low-level access to execute arbitrary code on a SharePoint server without any user interaction. On September 25, 2026, Microsoft confirmed it has reliable evidence of active attacks exploiting the flaw, and CISA added it to its Known Exploited Vulnerabilities catalog the same day with a federal remediation deadline of today, September 28, 2026. Threat intelligence firm Previdian has observed attackers chaining this vulnerability with a separate authentication bypass flaw to deliver an encrypted loader and establish full server control, effectively achieving unauthenticated remote code execution from what started as a low-priority patch. A critical detail for any organization reviewing its patch status is that closing the full exploitation path requires both the August 11 update and an earlier June 9 update, checking only the August build number can miss the exposure entirely. Organizations must confirm both updates are applied to every SharePoint farm, and review IIS and SharePoint Unified Logging Service logs for unusually large POST requests to /_layouts/15/ToolPane.aspx as an indicator of exploitation attempts.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.