CISA Adds CVE-2026-65660 in SharePoint to Actively Exploited Vulnerabilities
CISA added the CVE-2026-65660 vulnerability in on-premises Microsoft SharePoint servers to its KEV catalog. Microsoft has released fixes for three supported editions.

CVE-2026-65660 SharePoint has been added to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. agency CISA. CISA states that the vulnerability in on-premises Microsoft SharePoint servers is being actively exploited. Microsoft has released security updates for the affected products.
It is a code injection flaw that could allow an authenticated attacker to execute code remotely on the server. Microsoft assigned it a CVSS severity score of 8.8. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
CVE-2026-65660 SharePoint Is in the KEV Catalog
The KEV catalog collects vulnerabilities with known exploitation in the wild. For U.S. federal civilian agencies, CISA set a remediation deadline of September 28, 2026. This deadline does not directly apply to private organizations or entities outside the U.S. federal government, but the listing signals that administrators should prioritize the update.
An attacker must authenticate to exploit the flaw. That does not change the fact that successful exploitation could lead to code execution on the SharePoint server. On-premises SharePoint servers often process internal documents in organizations and may be connected to corporate identity systems.
Three On-Premises SharePoint Editions Are Affected
- SharePoint Enterprise Server 2016,
- SharePoint Server 2019,
- SharePoint Server Subscription Edition.
Operators of these products should identify servers running the relevant edition and deploy the cumulative updates provided by Microsoft for CVE-2026-65660. Since CISA has recorded active exploitation, this is not merely a preventive fix based on the CVSS score.
The factual scope of the attacks has not yet been publicly clarified. There is no confirmed information about the attackers’ identities, specific victims, or the number of compromised organizations. Public sources also do not provide enough technical detail to independently assess the exploitation technique being used or prepare specific indicators of compromise.
No Confirmed Link to Ransomware
There is currently no public confirmation that CVE-2026-65660 in SharePoint has been part of ransomware campaigns. Nor is there a credible attribution of the activity to a specific group. Organizations therefore should not infer a specific attack scenario from publicly available data beyond the confirmed active exploitation.
Further developments will depend on whether Microsoft or CISA publishes technical details, detection guidance, or indicators of compromise. Confirmation that relevant updates have been deployed in environments using supported on-premises SharePoint versions will also be important.
Sources
- Microsoft Security Response Center – Microsoft documents CVE-2026-65660 as a remote code execution vulnerability in supported on-premises SharePoint editions and provides security updates.
- CISA KEV Data – Official mirror of CISA data for the Known Exploited Vulnerabilities catalog; the catalog is intended for flaws with known active exploitation.
- SecurityWeek – Reports the addition of CVE-2026-65660 to CISA’s KEV catalog and the September 28, 2026 remediation deadline for federal agencies.
- OpenCVE – Publishes the CVE record with the flaw description, CVSS 8.8, and the affected SharePoint editions.
Verified and updated: 09/27/2026 15:22



