Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is now being exploited in attacks, roughly six weeks after Microsoft announced patches and a couple of days after researchers disclosed technical details.
CVE-2026-65660 is a remote code execution vulnerability fixed by Microsoft with its August 2026 Patch Tuesday updates. The company’s advisory describes it as a code injection issue that lets an authenticated attacker with low-level access to an affected server execute arbitrary code without user interaction.
“As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability,” Microsoft said in its updated advisory.
CISA added CVE-2026-65660 to its KEV catalog on September 25, giving federal agencies a patching deadline of September 28.
Early-warning threat intelligence platform Previdian (formerly KEVIntel) reported seeing exploitation attempts on September 24. On September 25, the company saw attempts to create a webshell backdoor.
It’s unclear who is behind the attacks,...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE