Microsoft Warns SharePoint Vulnerability CVE-2026-65660 Could Lead to Command Execution on Servers

Views: 44 views

Microsoft has revised the classification of CVE-2026-65660 in SharePoint Server, changing it from a spoofing vulnerability with a CVSS score of 6.5 to a High-severity Remote Code Execution (RCE) vulnerability with a CVSS score of 8.8 after additional details about its impact were disclosed. The vulnerability affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. An attacker with access to the system could exploit the vulnerability to execute commands on the server. Microsoft has already released security updates to address the issue.

The vulnerability stems from insufficient validation during SharePoint Web Part processing, which could allow an attacker to submit specially crafted data to load unauthorized .NET classes and ultimately execute commands through deserialization. Researchers also found that the vulnerability could be chained with a previously patched authentication bypass flaw to attack SharePoint servers with Anonymous Access enabled without requiring a user account. However, this attack method would not work if the related vulnerability has already been patched.

Administrators using SharePoint Server should review their update status and install Microsoft security patches as soon as possible, particularly on systems exposed to external networks. Technical details that could be used to exploit the vulnerability are now publicly available. However, there are currently no confirmed reports that CVE-2026-65660 has been exploited in real-world attacks, and the vulnerability has not been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

Source: https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html