Active exploitation is underway against CVE-2026-65660, a Microsoft SharePoint remote code execution flaw fixed in the August 2026 Patch Tuesday updates, roughly six weeks before attacks began and only a couple of days after researchers published technical details. CISA placed the issue in its KEV catalog on September 25, setting September 28 as the patching deadline for federal agencies. Microsoft states it had reliable evidence as of 9/25/2026 of observed attacks exploiting the vulnerability.
How the flaw works
Microsoft describes CVE-2026-65660 as a code injection weakness in SharePoint that allows a logged-in attacker with only low-level access to a vulnerable server to run arbitrary code with no victim interaction. Viettel Security, which reported the issue to Microsoft, said Microsoft first treated it as a medium-severity spoofing problem and later reclassified it as a high-severity remote code execution flaw.
In Microsoft's current characterization, the issue alone is an authenticated bypass of type checking that gives code execution to a low-privileged authenticated user. No user interaction is needed, but unauthenticated remote code execution is not possible with this flaw alone and would require combining it with a different authentication bypass weakness.
Exploitation timeline
The current activity appears to have started soon after Viettel Security released its technical description. Early-warning threat intelligence platform Previdian (formerly KEVIntel) said it observed exploitation attempts on September 24, followed on September 25 by attempts to plant a webshell backdoor. Previdian assessed that the exploits seen in the wild appeared to derive from the technical information shared by Viettel.
It remains unclear who is conducting the attacks. CISA added CVE-2026-65660 to its KEV catalog on September 25, with a September 28 remediation deadline for federal agencies. CISA's KEV catalog currently lists 16 SharePoint vulnerabilities, including eight discovered and patched this year.
Technical background
This section is general explanation, not specific to CVE-2026-65660.
Authenticated code injection occurs when server-side logic trusts input from a low-privileged session and passes it to a code evaluation or deserialization path. A type-check bypass is one variant: validation assumes a value is a benign type, but an attacker supplies an object that passes the check yet behaves as executable input downstream. By itself such a flaw still requires authentication; attackers often pair it with a separate authentication bypass to reach unauthenticated execution. A common post-exploitation goal after SharePoint or other server-side RCE is installation of a webshell to retain access.
Generic illustration of the pattern, not the actual exploit:
# Generic illustration only - not CVE-2026-65660 code
def process_input(data):
if isinstance(data, str):
# unsafe if caller can control content reaching exec/eval
handle(data)
else:
# incomplete validation can allow crafted objects through
handle(str(data))
Detection and mitigation
Microsoft fixed CVE-2026-65660 with its August 2026 Patch Tuesday updates, and organizations should apply those SharePoint fixes immediately given confirmed exploitation and the September 28 federal deadline. Prioritize internet-facing and internally exposed SharePoint servers, hunt for post-exploitation signs such as unexpected webshell backdoor creation noted around September 25, and review authentication logs for low-level accounts performing anomalous actions.
Relevant references: