• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65660: authorized code injection leading to remote code execution in Microsoft SharePoint

Certain Microsoft SharePoint Server branches contain a code injection vulnerability that can let an authorized attacker execute code over a network. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the listed 16.x releases prior to their respective fixed builds. An attacker must have an authorized account or privileges on the target SharePoint instance to exploit the vulnerability; successful exploitation can lead to full confidentiality, integrity, and availability impact on the server.

Published Updated Source: CVE Program, NVD, CISA KEV, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.02101
CWE
CWE-94
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Act urgently: this is a high-severity, network-exploitable code-injection flaw with public exploit code and CISA listing. Prioritize patching exposed SharePoint servers or apply vendor mitigations immediately.

What is CVE-2026-65660?

Certain Microsoft SharePoint Server branches contain a code injection vulnerability that can let an authorized attacker execute code over a network. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the listed 16.x releases prior to their respective fixed builds. An attacker must have an authorized account or privileges on the target SharePoint instance to exploit the vulnerability; successful exploitation can lead to full confidentiality, integrity, and availability impact on the server.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Which versions of Microsoft SharePoint are affected?

BRANCHAFFECTEDFIXED
Microsoft SharePoint Enterprise Server 2016 16.x16.0.0 – before 16.0.5565.100116.0.5565.1001
Microsoft SharePoint Server 2019 16.x16.0.0 – before 16.0.10417.2019816.0.10417.20198
Microsoft SharePoint Server Subscription Edition 16.x16.0.0 – before 16.0.19725.2052216.0.19725.20522

Is CVE-2026-65660 being exploited?

CISA lists this vulnerability as exploited in the wild and added it to their KEV catalog on 2026-09-25. Public exploit code for this issue is available. As of 2026-09-29, these are the known public exploitation facts.

How to fix CVE-2026-65660

  1. Apply the vendor fixes for your branch: upgrade to 16.0.5565.1001 (Enterprise Server 2016), 16.0.10417.20198 (Server 2019), or 16.0.19725.20522 (Subscription Edition).
  2. If you cannot patch immediately, restrict network exposure to SharePoint servers and limit access to trusted accounts only.
  3. Monitor SharePoint logs and system telemetry for unusual activity and signs of code execution.
  4. Follow vendor guidance and CISA KEV required actions for additional mitigations and forensics procedures.

Frequently asked questions

Is CVE-2026-65660 being actively exploited?

Yes. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2026-09-25, indicating reported exploitation in the wild.

Which SharePoint releases are fixed?

Fixed builds are 16.0.5565.1001 for Enterprise Server 2016, 16.0.10417.20198 for Server 2019, and 16.0.19725.20522 for Subscription Edition.

What does an attacker need to exploit this vulnerability?

An attacker requires an authorized account or privileges on the vulnerable SharePoint instance to carry out code injection and remote code execution.

References