SharePoint Server authenticated RCE (CVE-2026-65660)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-65660 in SharePoint Server is an authenticated remote code execution flaw affecting SharePoint Server 2016, 2019, and Subscription Edition. Microsoft had initially framed it as spoofing, but the published technical analysis shows a much higher-impact attack path. Patches were available since August 11, and defenders now need to treat the issue as a code-execution risk rather than a moderate spoofing bug.
Related Happenings
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Microsoft SharePoint remote code execution (CVE-2026-45659)
Vulnerability
H score17
First: 26.05.2026 14:49
Last: 26.05.2026 14:49
Sources 1
About this happening:
CVE-2026-45659 is a Microsoft SharePoint remote code execution vulnerability that affects unpatched SharePoint servers and can be triggered through deserializati...
Microsoft SharePoint remote code execution (CVE-2026-45659)
VulnerabilityAbout this happening: CVE-2026-45659 is a Microsoft SharePoint remote code execution vulnerability that affects unpatched SharePoint servers and can be triggered through deserializati...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Warlock ransomware post-exploitation tooling upgrades
Malware Activity
H score38
First: 17.03.2026 17:36
Last: 17.03.2026 17:36
Sources 1
About this happening:
The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Warlock ransomware post-exploitation tooling upgrades
Malware ActivityAbout this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
Timeline
-
22.09.2026 14:17 1 articles · 1h ago
Microsoft fixes CVE-2026-65660 in the August 11 SharePoint security updates
Mitigation Patch UpdateThe August 11 security updates fixed CVE-2026-65660 in SharePoint Server 2016, 2019, and Subscription Edition and turned off the vulnerable function by default, reducing exposure to the authenticated remote code execution path.
Show sources
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — thehackernews.com — 22.09.2026 14:17
-
22.09.2026 14:17 1 articles · 1h ago
Microsoft updates the CVE record for CVE-2026-65660 to describe remote code execution
Technical Analysis UpdateOn September 11, Microsoft updated the separate CVE record for CVE-2026-65660 to classify the flaw as a remote code execution vulnerability and to say that an authorized attacker can execute code, replacing the earlier spoofing framing.
Show sources
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — thehackernews.com — 22.09.2026 14:17
-
22.09.2026 14:17 2 articles · 1h ago
Viettel Cyber Security publishes full exploit details for SharePoint Server CVE-2026-65660
Initial DisclosureViettel Cyber Security researcher Dinh Ho Anh Khoa published full technical details showing CVE-2026-65660 in SharePoint Server can be exploited for authenticated remote code execution by abusing SafeControls checks and ToolPane Register directive handling; unescaped quotes let an attacker register arbitrary .NET classes, then use XamlServices.Parse() to reach code execution.
Show sources
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — thehackernews.com — 22.09.2026 14:17
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — thehackernews.com — 22.09.2026 14:17