Microsoft security patch release for CVE-2026-65660
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft's August 11 security updates shipped a fix for CVE-2026-65660 across SharePoint Server 2016, 2019, and Subscription Edition, reducing exposure to a flaw now understood to allow authenticated remote code execution. The patch matters because the vulnerability was initially framed as spoofing, but the underlying weakness supports code injection and arbitrary class loading. Microsoft also turned off the vulnerable function by default in the update. Defenders need to treat the release as a security fix for a code-execution issue, not a low-impact spoofing bug.
Related Happenings
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-71398
Security Patch Release
H score37
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Adobe security patch release for CVE-2026-71398
Security Patch ReleaseAbout this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Latest development: 12.08.2026 14:13
Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.
Microsoft YellowKey patch release (CVE-2026-45585)
Security Patch Release
H score20
First: 11.06.2026 20:43
Last: 11.06.2026 20:43
Sources 1
About this happening:
Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...
Microsoft YellowKey patch release (CVE-2026-45585)
Security Patch ReleaseAbout this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...
Microsoft June 2026 Patch Tuesday GreenPlasma and YellowKey fixes
Security Patch Release
H score15
First: 10.06.2026 02:11
Last: 10.06.2026 02:11
Sources 1
About this happening:
Microsoft released June 2026 Patch Tuesday updates that fixed the GreenPlasma and YellowKey flaws, closing two previously disclosed issues in the Windows ecosystem...
Microsoft June 2026 Patch Tuesday GreenPlasma and YellowKey fixes
Security Patch ReleaseAbout this happening: Microsoft released June 2026 Patch Tuesday updates that fixed the GreenPlasma and YellowKey flaws, closing two previously disclosed issues in the Windows ecosystem...
Timeline
-
22.09.2026 14:17 2 articles · 1h ago
Microsoft ships August 11 fix for CVE-2026-65660 in SharePoint Server
Mitigation Patch UpdateMicrosoft's August 11 security updates patched CVE-2026-65660 in SharePoint Server 2016, 2019, and Subscription Edition, and the update turns off the vulnerable function by default. The flaw was later understood to permit authenticated remote code execution through unescaped quotes in ToolPane Register directives, not just the spoofing impact described in Microsoft's advisory.
Show sources
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — thehackernews.com — 22.09.2026 14:17
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — thehackernews.com — 22.09.2026 14:17