CISA Adds Microsoft SharePoint Vulnerability to Actively Exploited Flaws

CISA added CVE-2026-65660 in on-premises Microsoft SharePoint to its catalog of actively exploited vulnerabilities. Fixes are available for the affected versions.

The Microsoft SharePoint vulnerability CVE-2026-65660 was added by the U.S. agency CISA to the Known Exploited Vulnerabilities (KEV) catalog on September 25, 2026. The entry means that the code injection flaw in Microsoft SharePoint Server is confirmed to be exploited in the wild.

The vulnerability could allow an authorized attacker to execute code on a vulnerable SharePoint server over the network. It affects on-premises Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in older builds.

Microsoft SharePoint vulnerability: affected versions and fixes

Updates are available for the individual affected product lines. Administrators should verify their deployment’s build number and install the applicable fix or a newer one.

  • SharePoint Enterprise Server 2016: build 16.0.5565.1001,
  • SharePoint Server 2019: build 16.0.10417.20198,
  • SharePoint Server Subscription Edition: build 16.0.19725.20522.

Canada’s Cyber Centre warned of active exploitation as early as September 24. It recommended that organizations update their servers, limit their exposure to the internet, and check their environments for possible signs of compromise.

KEV is a signal to prioritize patch deployment

The KEV catalog collects vulnerabilities for which CISA has recorded active exploitation. For CVE-2026-65660, this is therefore not merely a theoretical problem, but a flaw that administrators of unpatched SharePoint servers should address as a priority.

Internet-accessible instances deserve particular attention. The risk is that an attacker’s code could be executed on the server, although according to Microsoft, the individual vulnerability requires an authorized attacker.

The Cyber Centre also stated that this flaw could potentially be chained with other vulnerabilities to achieve pre-authentication remote code execution with anonymous access. However, it has not been publicly confirmed that such a scenario is independently available for CVE-2026-65660 or being used in recorded attacks.

Unknown scope of the attacks

There is no publicly confirmed information about the attackers’ identity, the scope of the campaign, or the number of compromised organizations.

Additional technical details and indicators of compromise may be included in future updates. The response of operators of SharePoint Server 2016 and 2019 systems, which are already unsupported product lines, will also be relevant.

Sources

Verified and updated: 09/26/2026 06:26

Sharing