Microsoft SharePoint CVE-2026-65660 Exploited in Attacks as CISA Deadline Hits

CISA has added SharePoint CVE-2026-65660 to its KEV catalog as researchers track exploitation attempts against on-premises servers and a Sept. 28 federal remediation deadline arrives.

Sep 28, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

CISA added Microsoft SharePoint vulnerability CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on Sept. 25, citing evidence of active exploitation.

The listing sets a Sept. 28 remediation deadline for affected federal civilian agencies under Binding Operational Directive 26-04 and requires forensic triage.

Canada's Cyber Centre reached the same conclusion a day earlier, warning that an authenticated attacker can exploit the flaw to run arbitrary code on vulnerable SharePoint servers. Chained with other SharePoint vulnerabilities, the flaw can also enable pre-authentication remote code execution on servers configured to permit anonymous access.

Security vendor Previdian initially recorded 12 exploitation requests from a single IP address on Sept. 24 and documented a two-stage attempt against its SharePoint honeypot.

The capture documents attempted exploitation against one Previdian honeypot, not evidence of a broad campaign or confirmed compromise.

Who's affected and what's already patched

CVE-2026-65660 affects SharePoint Server 2016, 2019, and Subscription Edition. Microsoft released the relevant Aug. 11 SharePoint security updates, with fixed builds of 16.0.19725.20522 for Subscription Edition, 16.0.10417.20198 for 2019, and 16.0.5565.1001 for 2016.

The applicable updates are KB5002893 for Subscription Edition, KB5002894 and KB5002896 for SharePoint Server 2019, and KB5002905 and KB5002906 for SharePoint Server 2016.

The vulnerability's paper trail is unusual. Microsoft first published the record on Aug. 11 as a spoofing issue rated 6.5, then revised it on Aug. 27 to a remote-code-execution issue rated 8.8. Previdian notes that Microsoft's live advisory records the change as informational and that the security update itself was still released Aug. 11.

The patch therefore did not arrive with the reclassification. Farms that had already installed the applicable August updates were protected against this CVE before Microsoft changed its description.

Organizations that have not fully applied prior SharePoint security updates face elevated risk. Canada's Cyber Centre says organizations should apply the latest Microsoft security updates rather than rely only on whether a particular CVE appears patched in an inventory tool.

Advertisement

SharePoint Server 2016 and 2019 also reached end of support on July 15. Microsoft's lifecycle documentation lists both products as past extended support, and the Cyber Centre recommends migrating affected deployments to a supported SharePoint version rather than treating this CVE as a one-off patch.

How to check for the CVE-2026-65660 SharePoint vulnerability

Confirming exposure comes down to build numbers, not the advisory label originally attached to the flaw.

Administrators should compare installed SharePoint builds with the fixed versions:

  • SharePoint Server Subscription Edition: 16.0.19725.20522 or later
  • SharePoint Server 2019: 16.0.10417.20198 or later
  • SharePoint Server 2016: 16.0.5565.1001 or later

Anything below those builds requires the applicable Microsoft security update.

For farms still running 2016 or 2019, the end-of-support status matters as much as the current patch. Those platforms require a migration plan because future security coverage cannot be assumed.

Exposure should also be checked directly. Earlier this year, more than 1,300 internet-facing SharePoint servers remained unpatched against another actively exploited SharePoint vulnerability after fixes were available.

CISA and Canada's mitigation guidance

CISA's Sept. 25 alert added CVE-2026-65660 to the KEV catalog with a Sept. 28 due date. The KEV entry also marks forensic triage as required under BOD 26-04.

For affected federal agencies, patching is therefore only part of the response. CISA's BOD 26-04 guidance calls for collecting and analyzing evidence to determine whether vulnerable systems were accessed, whether persistence was established, and whether attackers moved laterally or staged or exfiltrated data.

CISA's existing SharePoint hardening guidance recommends avoiding direct internet exposure where possible. If exposure is necessary, the agency recommends placing SharePoint behind a Layer 7 reverse proxy or equivalent application-layer control that requires authentication and can inspect and filter inbound requests.

CISA also recommends enabling Antimalware Scan Interface integration for SharePoint web applications and configuring Full Mode request-body scanning where operationally feasible.

Advertisement

The Canadian Cyber Centre recommends restricting access to SharePoint Central Administration and other management interfaces, removing unnecessary or inactive accounts, enforcing multi-factor authentication for administrators and other privileged users, and monitoring SharePoint, IIS, endpoint, and authentication logs.

Neither agency presents AMSI as a substitute for patching. It is an additional defensive layer for detecting or blocking malicious web requests.

SharePoint exploitation has previously progressed to ransomware deployment on vulnerable systems. Organizations that find evidence of exploitation should therefore investigate for compromise rather than assume installing the update removes anything an attacker may already have placed on the server.

What CVE-2026-65660 exploitation looks like in logs

Previdian's Sept. 24 technical write-up documents 12 POST requests from one source IP across six URL paths. Its live exploitation telemetry now lists 16 attempts associated with CVE-2026-65660 from two attacker IPs as of Sept. 28.

The original burst targeted two SharePoint paths:

/_layouts/15/AddGallery.aspx

/_layouts/15/designgallery.aspx

The requests carried the query string job=all&DisplayMode=Edit and form fields named MSOTlPn_Uri and MSOTlPn_DWP.

None of the 12 requests in the original capture carried cookies or an Authorization header. They came from 169.150.248[.]21 and used a Firefox 120 user agent.

The traffic arrived in two paired payloads on each of six paths: one 7,834 bytes and the other 535,404 bytes.

Previdian identified the smaller payload as an ActivitySurrogateDisableTypeCheck gadget. The larger payload contained an ActivitySurrogate gadget and an embedded assembly named wt3k3sij.dll, which included a loader type called SdLoader.

The loader contained AES decryption routines and a call to Assembly.Load(byte[]), consistent with an attempt to decrypt and execute an additional assembly in memory.

Previdian later identified a webshell path associated with the exploitation activity:

/_layouts/15/sphealth.aspx

Defenders should also look for repeated /_layouts/ path segments, DisplayMode=Edit, closely timed requests from the same source, and unexpected activity involving the identified DLL and loader names.

These indicators come from Previdian's sensor data and should not be treated as a complete list of attacker infrastructure or exploitation techniques.

Advertisement

How the two-stage exploit chain works

CVE-2026-65660 itself requires authentication. Microsoft's advisory describes an attacker with low-level authenticated access sending a crafted network request to execute code on the server.

Previdian's captured traffic attempted to bypass that requirement by pairing CVE-2026-65660 with a separate anonymous-delivery weakness affecting SharePoint sites configured to permit anonymous viewing.

According to Previdian, the anonymous delivery path was fixed on June 9. The SafeControls quote-injection vulnerability tracked as CVE-2026-65660 was fixed on Aug. 11.

The two flaws address separate parts of the attempted chain. Fixing the June issue closes the anonymous route described in the research, while remediating CVE-2026-65660 still requires the applicable August security update.

Previdian also cautions that it has not demonstrated that every captured request variant successfully compromises a real SharePoint deployment.

What happens after the loader executes is also unresolved. The final decrypted assembly was not recovered, so the attacker's ultimate objective remains unconfirmed.

Organizations that installed the applicable August updates are protected against CVE-2026-65660. Organizations exposed before patching should also review the published indicators, inspect systems for webshells or other persistence, and complete compromise checks rather than treating patch installation alone as evidence the server is clean.

Also read: An actively exploited F5 BIG-IP zero-day recently received another three-day CISA remediation deadline for affected federal systems.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.