CVE-2026-65660: SharePoint Flaw Under Active Attack, Patch Now
CVE-2026-65660 lets authenticated attackers hijack on-premises SharePoint Server via a ToolPane code-injection bug. CISA confirms active exploitation and sets a September 28 deadline.
Microsoft SharePoint Server administrators need to patch today, not this week. CVE-2026-65660, a code-injection flaw in on-premises SharePoint Server, is being actively exploited right now — attackers have been spotted dropping webshells since September 24–25 — and the Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities (KEV) catalog with a hard deadline of September 28, 2026 for federal agencies to remediate. Microsoft shipped a fix for this bug back in its August 2026 Patch Tuesday release, so any organization that installed that update weeks ago is already protected. Everyone else is now a target.
Quick facts: CVE-2026-65660
- CVE ID: CVE-2026-65660
- CVSS v3.1 score: 8.8 (High) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weakness: CWE-94, Improper Control of Generation of Code (code injection)
- Affected product: On-premises Microsoft SharePoint Server 2016, 2019 and Subscription Edition (SharePoint Online / Microsoft 365 is not affected)
- Patch status: Fixed — security updates released August 11, 2026
- Exploitation: Confirmed active in the wild by Microsoft as of September 25, 2026
- CISA KEV deadline: September 28, 2026 (federal civilian agencies)
What happened
CVE-2026-65660 is a remote code execution vulnerability in on-premises SharePoint Server that Microsoft quietly patched in its August 2026 security release. For weeks it drew little attention — Microsoft's own advisory initially rated exploitation "less likely" and, in an odd twist, an earlier version of the write-up even described the flaw's impact as spoofing rather than code execution. On August 27, Microsoft revised the advisory to correct the CVE title and the impact listed in its security-updates table, clarifying that the bug is a genuine remote code execution issue, not a spoofing bug.
That changed fast in late September. Technical details about the flaw began circulating after security researchers at Viettel published analysis of the bug on September 24. Within a day, threat-intelligence monitoring began recording exploitation attempts against internet-facing SharePoint servers, including attackers dropping webshells to maintain persistent access. Microsoft updated its official advisory on September 25 to state it had "reliable evidence of observed attacks" exploiting the vulnerability. CISA added CVE-2026-65660 to its KEV catalog that same day, which under Binding Operational Directive 26-04 gives federal civilian agencies a three-day window to patch — a deadline that lands this Monday, September 28.
This is now the third on-premises enterprise product in a matter of weeks to land on Pandromeda's security desk with confirmed in-the-wild exploitation, following the Check Point VPN vulnerabilities and the F5 BIG-IP APM flaw covered earlier this week. Internet-facing enterprise infrastructure — VPN gateways, load balancers, and now collaboration servers — is clearly the priority target list for attackers right now.
What CVE-2026-65660 actually is
SharePoint Server includes a built-in editing surface called the ToolPane, which is used to configure web parts (the modular content blocks that make up a SharePoint page). When SharePoint processes the markup for a web part, it has to reconstruct "Register" directives — the instructions that tell the server which .NET classes are allowed to run on a page — and it does this by writing attribute values wrapped in double quotes.
The bug is that SharePoint fails to escape double-quote characters that appear inside those attribute values. An authenticated attacker — even one with only low-level, minimally privileged access to the server — can craft a web-part payload that uses an unescaped quote to break out of the intended attribute and inject an entirely new Register directive of their own. Because the injected directive runs after SharePoint's normal type-check has already completed, it bypasses the SafeControls list, the allow-list SharePoint is supposed to use to restrict which .NET classes can be loaded on a page. With that restriction bypassed, the attacker can register an arbitrary .NET class of their choosing.
From there, the attack chain reaches code execution through .NET's XamlServices.Parse() method, which SharePoint uses to deserialize XAML content. Attackers can point the now-registered arbitrary class at a malicious payload and get it parsed and executed via that deserialization call, giving them remote code execution on the server with no user interaction required from an administrator or any other user — the CVSS vector's "UI:N" rating reflects exactly that.
Both Microsoft's own advisory and NVD's CVE record score CVE-2026-65660 at CVSS v3.1 base 8.8 (High), reflecting a network-exploitable, low-complexity attack that needs only low privileges and yields high impact to confidentiality, integrity and availability alike. Microsoft's temporal score (7.7) is slightly lower once available exploit maturity and remediation status are factored in — but that number was already outdated the moment mass exploitation attempts began.
Why "authenticated" doesn't mean "low risk"
On paper, CVE-2026-65660 requires an attacker to already hold low-privilege credentials on the target SharePoint server — it is not, by itself, an unauthenticated bug. In practice, that has provided little comfort. Security researchers tracking the September exploitation wave have reported that some attackers are chaining CVE-2026-65660 with a separate, unauthenticated vulnerability that lets them reach the flaw without ever needing valid credentials at all, effectively producing end-to-end unauthenticated remote code execution against unpatched, internet-facing servers. Organizations should treat any internet-facing, unpatched SharePoint Server as exploitable by an anonymous attacker, not just an insider or an attacker who has separately obtained low-level credentials through phishing or credential stuffing.
Who's affected
CVE-2026-65660 affects on-premises, self-hosted SharePoint Server deployments only. According to Microsoft's advisory and NVD's Common Platform Enumeration data, the affected products and fixed builds are:
| Product | Vulnerable if build is earlier than | Security update (KB) |
|---|---|---|
| SharePoint Enterprise Server 2016 / SharePoint Server 2016 | 16.0.5565.1001 | KB5002905, KB5002906 |
| SharePoint Server 2019 | 16.0.10417.20198 | KB5002894, KB5002896 |
| SharePoint Server Subscription Edition | 16.0.19725.20522 | KB5002893 |
SharePoint Online, part of Microsoft 365, is not affected. Microsoft's cloud service is patched centrally and was never vulnerable to this specific on-premises flaw; organizations that have fully migrated to SharePoint Online have nothing to patch here. This is purely an on-premises server issue, which makes it disproportionately dangerous for the kinds of organizations — government agencies, universities, manufacturers, healthcare systems — that still run SharePoint Server in-house for compliance, data-residency or legacy-integration reasons.
Timeline: disclosure to exploitation
| Date | Event |
|---|---|
| August 11, 2026 | Microsoft ships fixes for CVE-2026-65660 as part of its August 2026 Patch Tuesday release; advisory initially rates exploitation "less likely." |
| August 27, 2026 | Microsoft revises the advisory, correcting the CVE title and impact classification from spoofing to remote code execution (informational update only, no code change). |
| September 24, 2026 | Security researchers publish technical analysis of the vulnerability; first exploitation attempts observed the same day. |
| September 25, 2026 | Webshell deployment attempts detected against unpatched servers; Microsoft updates its advisory to confirm "reliable evidence of observed attacks"; CISA adds CVE-2026-65660 to the KEV catalog. |
| September 28, 2026 | CISA's Binding Operational Directive 26-04 deadline for U.S. federal civilian agencies to have remediated the vulnerability. |
CISA's KEV listing and what the deadline means
CISA's Known Exploited Vulnerabilities catalog exists specifically to flag vulnerabilities with confirmed real-world exploitation, and listing on it triggers Binding Operational Directive 26-04, which requires U.S. federal civilian executive branch agencies to remediate within a set window — three business days for this entry, running to September 28. CISA's guidance for this listing directs agencies to apply the vendor's mitigations, follow BOD 26-04's forensic-triage requirements where applicable, and, if mitigations aren't available for a given asset, to discontinue use of the product until they are.
Federal agencies are the ones legally bound by that deadline, but the KEV catalog is a widely used signal well beyond government. State and local governments, contractors, and private-sector security teams routinely treat a KEV listing as their own internal "patch now" trigger, because it means CISA has verified exploitation is not theoretical — it's already happening against real targets.
How to patch and mitigate
The fix for CVE-2026-65660 has been publicly available since August 11, 2026, so remediation is primarily a matter of confirming it has actually been applied:
- Apply the August 2026 security updates for your SharePoint Server edition (see the version table above) via Microsoft Update, WSUS, or manual installation from the Microsoft Update Catalog, then confirm your farm's build number matches or exceeds the fixed build listed for your edition.
- Patch every server in the farm, not just the front-end web servers — SharePoint farms often include multiple application and search servers that also need the update applied and the SharePoint Products Configuration Wizard run afterward.
- Restrict internet exposure where full patching can't happen immediately: limit which IP ranges can reach your SharePoint Server front end, and ensure a web application firewall or reverse proxy sits in front of internet-facing farms.
- Rotate machine keys after patching. Historical SharePoint deserialization attacks have shown that if a server's ASP.NET machine keys were exposed prior to patching, an attacker can sometimes continue to forge valid requests even after the underlying bug is fixed — Microsoft's guidance for prior SharePoint RCE incidents has recommended rotating these keys and restarting IIS as a precaution.
- Tighten account privileges on the SharePoint farm and require strong, phishing-resistant authentication for any accounts with even low-level access, since CVE-2026-65660 only requires an authenticated low-privilege session to begin the attack chain. If your organization hasn't already rolled out app-based multi-factor authentication for internal admin and service accounts, our guide to setting up an authenticator app for two-factor authentication covers the setup process.
- If you cannot patch or otherwise mitigate an internet-facing farm immediately, CISA's guidance is blunt: take the affected service offline until you can.
How to check if you've already been compromised
Because exploitation has been observed since September 24–25, any unpatched, internet-facing SharePoint Server should be treated as potentially already compromised, not just vulnerable. Steps worth taking immediately:
- Check current build numbers against the fixed builds in the table above across every server in the farm — an unpatched server that has been internet-reachable since before September 24 warrants the closest scrutiny.
- Look for unfamiliar files in web-accessible SharePoint directories, particularly newly created .aspx files in layouts or web-part directories that you don't recognize from your own deployment history — a classic sign of a dropped webshell.
- Review IIS and SharePoint ULS logs for unusual POST requests to ToolPane-related endpoints and for process activity spawned from the SharePoint application pool identity around and after September 24.
- Check for new or modified scheduled tasks, services, or local accounts created around the same window, which attackers commonly use to maintain persistence after an initial webshell foothold.
- Engage incident response support if you find any of the above. CISA's Known Exploited Vulnerabilities program pairs with forensic-triage guidance under BOD 26-04 for exactly this scenario, and Microsoft's advisory is the authoritative source for indicators as they're updated.
If your organization already applied the August updates before September 24, the evidence so far indicates you were not exposed to the active exploitation wave — but it's still worth confirming build numbers rather than assuming.
What's next
Expect Microsoft's advisory and CISA's KEV entry to keep evolving over the coming days as more detail emerges about the chained unauthenticated delivery technique attackers are using. Federal agencies are working against the September 28 deadline this weekend, and private-sector organizations running on-premises SharePoint Server should treat that same date as their own target if they haven't patched yet. Given that this is now the third actively exploited on-premises enterprise product disclosed on Pandromeda's security desk in the space of a week — alongside the Check Point and F5 issues — organizations that manage a mix of edge and collaboration infrastructure should use this moment to do a full sweep of patch status across all of it, not just SharePoint, and to confirm nothing else on that list is still sitting unpatched behind a public IP address. We'll update this article if Microsoft or CISA publish new indicators of compromise or revise the advisory further.
Frequently asked questions
What is CVE-2026-65660?
CVE-2026-65660 is a code-injection vulnerability (CVSS 8.8, High) in on-premises Microsoft SharePoint Server. It occurs because the ToolPane component fails to escape double quotes in web-part markup, letting an authenticated attacker register arbitrary .NET classes outside SharePoint's SafeControls allow-list and trigger remote code execution via .NET's XamlServices.Parse() deserialization method.
Is SharePoint Online or Microsoft 365 affected?
No. CVE-2026-65660 only affects on-premises SharePoint Server deployments — SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. SharePoint Online, part of Microsoft 365, is not affected.
Is CVE-2026-65660 actually being exploited?
Yes. Microsoft updated its official advisory on September 25, 2026 to confirm it had reliable evidence of observed attacks exploiting the vulnerability, including webshells deployed against unpatched servers starting around September 24.
What is CISA's deadline for CVE-2026-65660?
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25, 2026, setting a remediation deadline of September 28, 2026 for U.S. federal civilian agencies under Binding Operational Directive 26-04.
How do I patch CVE-2026-65660?
Install Microsoft's August 2026 security updates for your SharePoint Server edition: KB5002905/KB5002906 for SharePoint Server 2016, KB5002894/KB5002896 for SharePoint Server 2019, or KB5002893 for SharePoint Server Subscription Edition, then confirm the build number on every server in the farm.
What should I do if I can't patch my SharePoint Server immediately?
Restrict internet access to the server, put a web application firewall or reverse proxy in front of it, tighten account privileges and require strong authentication, and if no mitigation is possible, CISA's guidance is to take the service offline until it can be patched.
Sources
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


