Skip to main content

Exploitation of Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-65660

Exploitation of CVE-2026-65660 could allow an authenticated attacker with low-level access to an affected server the ability to execute code on the server

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Exploitation of CVE-2026-65660 could allow an authenticated attacker with low-level access to an affected server the ability to execute code on the server


Threat details

Exploitation of CVE-2026-65660

Microsoft has observed exploitation of CVE-2026-65660. The US Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses continued exploitation as likely.


Introduction

Microsoft released security updates in August 2026 to address CVE-2026-65660 in SharePoint Server. Successful exploitation of this vulnerability could allow an authenticated attacker with low-level access to an affected server to achieve remote code execution on SharePoint servers via a specially crafted request sent to the server.

  • CVE-2026-65660 - Code injection vulnerability - CVSS v3.1 score - 8.8

Remediation advice

Affected organisations are strongly encouraged to review Microsoft's Security Update Guide - CVE-2026-65660 advisory and apply the relevant update as soon as possible.



Last edited: 28 September 2026 1:55 pm