LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 25, 2026
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on Sep 25, 2026, with a federal patch deadline of Sep 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Overview

CVE-2026-65660 is a code injection vulnerability in Microsoft SharePoint. According to CISA, an authorized attacker could use it to execute code over a network. That matters because SharePoint often holds documents, collaboration data, and integrations that many organizations treat as sensitive or business-critical.

Public detail in the provided record is limited to the product, the CWE class, and the high-level impact. Exact affected builds, scoring, and exploit mechanics must be confirmed against the vendor advisory before you act on version-specific claims.

How it works

This issue is tracked as CWE-94 (code injection). In that weakness class, software accepts input or content that is later interpreted or executed in a privileged context without sufficient validation or isolation. An attacker who already has some authorized access can abuse the flaw to cause the application to run attacker-controlled code in the SharePoint environment rather than only processing data as intended.

CISA’s summary states the outcome as code execution over a network by an authorized attacker. Do not assume unauthenticated remote exploit, specific request paths, or payload formats unless the vendor advisory documents them. Treat this as a post-authentication (or otherwise authorized) code-execution risk in the SharePoint attack surface until you verify the precise preconditions with Microsoft.

Am I affected? How to find it in your systems

Microsoft SharePoint commonly runs as on-premises server farms, hybrid deployments, or related Microsoft 365 / SharePoint Online services depending on your architecture. Inventory every SharePoint role: web front ends, application servers, search, workflow hosts, and any reverse proxies or load balancers in front of them.

How to remediate

Patch first: apply the Microsoft updates and mitigations named in the vendor advisory for CVE-2026-65660, and follow CISA’s required action to apply mitigations in accordance with vendor instructions while ensuring compliance with BOD 26-04 prioritization and related forensics triage expectations. For cloud-hosted SharePoint services, follow applicable BOD 26-04 cloud guidance; if mitigations are unavailable, discontinue use of the product as directed in that guidance framework.

If you can't patch immediately

Reduce exposure until the vendor fix is installed. Compensating controls for this class of SharePoint code-injection risk include:

These steps lower likelihood and blast radius; they are not a permanent replacement for the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches of document libraries, lists, and connected systems even when ransomware use is not documented for this CVE. If you suspect exploitation, follow your incident response plan, preserve SharePoint and identity logs, and complete forensics triage consistent with CISA’s referenced requirements. As a simple personal check, you can run a free exposure scan of your email address against known breach datasets to see whether your credentials or related identities already appear in public breach collections, then force resets and session revocation where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-94
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedAug 11, 2026
Added to CISA KEVSep 25, 2026
Federal patch deadlineSep 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities