Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Microsoft SharePoint vulnerability CVE-2026-65660 is being actively exploited, with evidence of attacks appearing soon after Microsoft’s August 2026 patch and Viettel Security’s technical disclosure. The flaw allows authenticated attackers with low-level access to execute arbitrary code, and CISA has already added it to the KEV catalog with a rapid federal patch deadline. #CVE-2026-65660 #MicrosoftSharePoint #CISA #ViettelSecurity #KEV

Keypoints

  • CVE-2026-65660 in Microsoft SharePoint is now being exploited in the wild.
  • The vulnerability is a remote code execution flaw fixed in Microsoft’s August 2026 Patch Tuesday updates.
  • Microsoft said it had reliable evidence of observed attacks by September 25, 2026.
  • CISA added CVE-2026-65660 to its KEV catalog and set a September 28 patch deadline for federal agencies.
  • Threat intelligence reports showed attempts to create a webshell backdoor after technical details were disclosed.

Read More: https://www.securityweek.com/microsoft-sharepoint-flaw-cve-2026-65660-now-exploited-in-attacks/