DIRAS TAKE
Act urgently: this is a high-severity, network-exploitable code-injection flaw with public exploit code and CISA listing. Prioritize patching exposed SharePoint servers or apply vendor mitigations immediately.
What is CVE-2026-65660?
Certain Microsoft SharePoint Server branches contain a code injection vulnerability that can let an authorized attacker execute code over a network. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the listed 16.x releases prior to their respective fixed builds. An attacker must have an authorized account or privileges on the target SharePoint instance to exploit the vulnerability; successful exploitation can lead to full confidentiality, integrity, and availability impact on the server.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Which versions of Microsoft SharePoint are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft SharePoint Enterprise Server 2016 16.x | 16.0.0 – before 16.0.5565.1001 | 16.0.5565.1001 |
| Microsoft SharePoint Server 2019 16.x | 16.0.0 – before 16.0.10417.20198 | 16.0.10417.20198 |
| Microsoft SharePoint Server Subscription Edition 16.x | 16.0.0 – before 16.0.19725.20522 | 16.0.19725.20522 |
Is CVE-2026-65660 being exploited?
CISA lists this vulnerability as exploited in the wild and added it to their KEV catalog on 2026-09-25. Public exploit code for this issue is available. As of 2026-09-29, these are the known public exploitation facts.
How to fix CVE-2026-65660
- Apply the vendor fixes for your branch: upgrade to 16.0.5565.1001 (Enterprise Server 2016), 16.0.10417.20198 (Server 2019), or 16.0.19725.20522 (Subscription Edition).
- If you cannot patch immediately, restrict network exposure to SharePoint servers and limit access to trusted accounts only.
- Monitor SharePoint logs and system telemetry for unusual activity and signs of code execution.
- Follow vendor guidance and CISA KEV required actions for additional mitigations and forensics procedures.
Frequently asked questions
Is CVE-2026-65660 being actively exploited?
Yes. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2026-09-25, indicating reported exploitation in the wild.
Which SharePoint releases are fixed?
Fixed builds are 16.0.5565.1001 for Enterprise Server 2016, 16.0.10417.20198 for Server 2019, and 16.0.19725.20522 for Subscription Edition.
What does an attacker need to exploit this vulnerability?
An attacker requires an authorized account or privileges on the vulnerable SharePoint instance to carry out code injection and remote code execution.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65660
- cve.org/CVERecord?id=CVE-2026-65660
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026