Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

https://www.securityweek.com/wp-content/uploads/2026/07/SharePoint.jpeg

A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is now being exploited in attacks, roughly six weeks after Microsoft announced patches and a couple of days after researchers disclosed technical details.

CVE-2026-65660 is a remote code execution vulnerability fixed by Microsoft with its August 2026 Patch Tuesday updates. The company’s advisory describes it as a code injection issue that lets an authenticated attacker with low-level access to an affected server execute arbitrary code without user interaction.

“As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability,” Microsoft said in its updated advisory.

CISA added CVE-2026-65660 to its KEV catalog on September 25, giving federal agencies a patching deadline of September 28.

Early-warning threat intelligence platform Previdian (formerly KEVIntel) reported seeing exploitation attempts on September 24. On September 25, the company saw attempts to create a webshell backdoor.

It’s unclear who is behind the attacks,...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more