Exploitation of Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-65660
Exploitation of CVE-2026-65660 could allow an authenticated attacker with low-level access to an affected server the ability to execute code on the server
Summary
Exploitation of CVE-2026-65660 could allow an authenticated attacker with low-level access to an affected server the ability to execute code on the server
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-65660
Microsoft has observed exploitation of CVE-2026-65660. The US Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses continued exploitation as likely.
Introduction
Microsoft released security updates in August 2026 to address CVE-2026-65660 in SharePoint Server. Successful exploitation of this vulnerability could allow an authenticated attacker with low-level access to an affected server to achieve remote code execution on SharePoint servers via a specially crafted request sent to the server.
- CVE-2026-65660 - Code injection vulnerability - CVSS v3.1 score - 8.8
Remediation advice
Affected organisations are strongly encouraged to review Microsoft's Security Update Guide - CVE-2026-65660 advisory and apply the relevant update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 28 September 2026 1:55 pm