At a glance:
-
CVE-2026-65660 is an actively exploited SharePoint flaw allowing an authenticated low-privileged user to execute code on an on-premises SharePoint server. POC was released September 22, and exploitation attempts were observed within days.
-
The authentication requirement may provide limited protection in environments where threat actors can obtain valid credentials through phishing, password spraying, credential theft, or a previous compromise. Researchers also demonstrated a separate attack chain that removed the authentication requirement on specific unpatched SharePoint deployments.
-
Apply the updates, and review SharePoint, Internet Information Services (IIS), and endpoint telemetry for signs of exploitation, including unexpected activity originating from w3wp.exe and memory-resident web shells.
Threat summary
On September 25, 2026, CISA added a vulnerability affecting on-premises SharePoint Server deployments to the Known Exploited Vulnerabilities Catalog after evidence emerged that threat actors were attempting to compromise vulnerable systems.
Public technical details became available on September 22, 2026, when researchers disclosed the root cause and published proof-of-concept (PoC) code. Within days, security monitoring providers reported exploitation attempts targeting vulnerable systems.
Microsoft released patches for the vulnerability, tracked as CVE-2026-65660, on August 11, 2026. At the time, the vulnerability was described as a spoofing issue and assigned a CVSS score of 6.5.
In September, updates to the CVE record and technical analysis published by security researchers established that the vulnerability could be used by an authenticated user to execute code on an affected SharePoint server. The National Vulnerability Database subsequently assigned the vulnerability a CVSS score of 8.8.
Affected products include:
SharePoint Online is not listed as affected.
About CVE-2026-65660
CVE-2026-65660 affects how SharePoint processes web parts, components that add functionality to SharePoint pages. Before loading a web part, SharePoint uses a security mechanism called SafeControls to verify that the associated .NET component is approved for use. Published research showed that a flaw in SharePoint's ToolPane component allows a threat actor to manipulate web part markup after this validation occurs.
By injecting additional registration directives, a threat actor can cause SharePoint to load classes that were not approved by the SafeControls process. The CVE states that exploitation requires a valid SharePoint account and network access to the SharePoint application. A low-privileged authenticated user can exploit the vulnerability remotely without user interaction.
The PoC demonstrated a potential post-exploitation technique that may reduce the visibility of activity that relies primarily on detecting web-shell files. After bypassing the SafeControls validation process, the researcher demonstrated code execution through the XamlServices.Parse() functionality and deployed an in-memory web shell that operated from process memory rather than from a file written to disk. This demonstrates one way a threat actor could maintain access to a compromised SharePoint server while leaving fewer file-based artifacts for defenders to investigate.
Separately, the researcher demonstrated that the requirement for a valid SharePoint account could be removed by combining CVE-2026-65660 with a previously patched (unnamed) SharePoint authentication bypass vulnerability. On affected deployments that allowed anonymous page access and had not received the earlier fix, the combined chain enabled unauthenticated users to reach the vulnerable functionality and execute code on the SharePoint server without first obtaining credentials.
Analysis
SharePoint servers occupy a unique position in many enterprise environments. Beyond storing documents, they frequently serve as a central hub for collaboration, workflow automation, knowledge management, and integration with other business systems.
A successful compromise can provide access to information that is difficult to obtain through attacks against individual endpoints. SharePoint repositories often contain contracts, financial records, operational documentation, project data, and other information that can support espionage, fraud, extortion, or follow-on intrusion activity.
The recent history of SharePoint exploitation showed threat actors targeting SharePoint vulnerabilities to gain persistent access to enterprise environments, deploy web shells, and access sensitive organizational data. Because SharePoint is commonly trusted by users and administrators, activity originating from a compromised SharePoint server may initially appear legitimate, providing adversaries with opportunities to blend into normal operations.
SharePoint servers frequently maintain connections to identity services, databases, file repositories, and business applications. Access to one SharePoint server can therefore expose information and resources that extend well beyond the platform. The impact of a compromise depends heavily on the data stored within SharePoint, the permissions available to the application, and the systems it can access.
Although the vulnerability is classified as authenticated, the practical barrier to exploitation may be lower than the requirement suggests. SharePoint is commonly accessible to large numbers of users and often exposed through remote-access infrastructure. Threat actors that obtain valid credentials through phishing, password spraying, credential theft, or an earlier compromise may already satisfy the authentication requirement.
Mitigations
Upgrade SharePoint Server 2016, 2019, and Subscription Edition to the August 2026 security updates to remove the vulnerable code path used in active exploitation. Verify that June 2026 SharePoint security updates are also installed to prevent the authentication-bypass chain demonstrated by researchers from removing the credential requirement.
Review SharePoint permissions and remove unnecessary user access to reduce the number of accounts that could be used to exploit the vulnerability. Review configurations that allow anonymous page access to eliminate a condition required for the unauthenticated attack chain demonstrated in the proof of concept. Limit direct internet access to SharePoint services through virtual private networks (VPNs), reverse proxies, or access controls to reduce opportunities for external threat actors to reach vulnerable systems.
Monitor for child processes spawned by w3wp.exe, PowerShell execution, command shells, scripting engines, and unexpected outbound network connections from SharePoint servers to help identify post-exploitation activity. Review endpoint telemetry for memory-resident activity to help detect in-memory web shells that may not create files on disk. Review SharePoint and Internet Information Services (IIS) logs for unusual authentication activity, unexpected administrative actions, and suspicious use of low-privileged accounts to help identify exploitation attempts or compromised credentials.