CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Overview
CVE-2026-65660 is a code injection vulnerability in Microsoft SharePoint. According to CISA, an authorized attacker could use it to execute code over a network. That matters because SharePoint often holds documents, collaboration data, and integrations that many organizations treat as sensitive or business-critical.
Public detail in the provided record is limited to the product, the CWE class, and the high-level impact. Exact affected builds, scoring, and exploit mechanics must be confirmed against the vendor advisory before you act on version-specific claims.
How it works
This issue is tracked as CWE-94 (code injection). In that weakness class, software accepts input or content that is later interpreted or executed in a privileged context without sufficient validation or isolation. An attacker who already has some authorized access can abuse the flaw to cause the application to run attacker-controlled code in the SharePoint environment rather than only processing data as intended.
CISA’s summary states the outcome as code execution over a network by an authorized attacker. Do not assume unauthenticated remote exploit, specific request paths, or payload formats unless the vendor advisory documents them. Treat this as a post-authentication (or otherwise authorized) code-execution risk in the SharePoint attack surface until you verify the precise preconditions with Microsoft.
Am I affected? How to find it in your systems
Microsoft SharePoint commonly runs as on-premises server farms, hybrid deployments, or related Microsoft 365 / SharePoint Online services depending on your architecture. Inventory every SharePoint role: web front ends, application servers, search, workflow hosts, and any reverse proxies or load balancers in front of them.
- Build an asset list from configuration management, Microsoft 365 admin centers, server inventory, and software bill-of-materials tools that flag SharePoint products and cumulative updates.
- Record build numbers, patch levels, and whether each farm is internet-exposed, partner-exposed, or internal-only. Stakeholders should evaluate internet exposure as called out in CISA’s BOD 26-04-oriented guidance.
- Confirm which versions and configurations are listed as affected in the vendor advisory; do not rely on guessed version ranges.
- Review identity and access logs for unusual authenticated activity against SharePoint URLs, sudden process creation under SharePoint worker identities, unexpected web shell–like artifacts in content or layout directories (only as general post-exploitation hygiene for this class), and anomalous outbound connections from SharePoint hosts.
- Correlate with SIEM detections for privileged SharePoint service accounts performing atypical admin or code-hosting actions. Absence of public ransomware attribution in the given facts does not mean compromise is harmless.
How to remediate
Patch first: apply the Microsoft updates and mitigations named in the vendor advisory for CVE-2026-65660, and follow CISA’s required action to apply mitigations in accordance with vendor instructions while ensuring compliance with BOD 26-04 prioritization and related forensics triage expectations. For cloud-hosted SharePoint services, follow applicable BOD 26-04 cloud guidance; if mitigations are unavailable, discontinue use of the product as directed in that guidance framework.
- After patching, verify build levels across all farm members and validate that temporary workarounds are removed only when the permanent fix is confirmed.
- Harden for the code-injection class: minimize accounts that can upload or influence executable or scriptable content; enforce least privilege on SharePoint service and application pool identities; restrict who can deploy solutions, custom web parts, or server-side extensions.
- Ensure management interfaces are not broadly reachable; require strong authentication and conditional access where applicable.
- Re-baseline file integrity and process allow-listing on SharePoint servers after remediation so residual unauthorized code is easier to spot.
If you can't patch immediately
Reduce exposure until the vendor fix is installed. Compensating controls for this class of SharePoint code-injection risk include:
- Network segmentation and strict allow-lists so only necessary clients reach SharePoint HTTP/HTTPS endpoints; remove or lock down internet exposure where business allows.
- Virtual patching or WAF rules only if your vendor or a trusted defensive feed provides signatures tied to this CVE—generic rules are incomplete substitutes and must be validated so they do not break legitimate traffic.
- Disable or tightly restrict features that accept rich or executable content, custom code deployment, or high-risk server-side extensibility if your operations can tolerate it and the advisory supports that option.
- Heighten monitoring on authenticated sessions, SharePoint ULS/IIS logs, and host EDR for code execution under SharePoint identities; alert on new binaries, scripts, or unusual child processes.
- Rotate and vault credentials for highly privileged SharePoint and farm admin accounts; review recent permission changes.
These steps lower likelihood and blast radius; they are not a permanent replacement for the vendor update.
If your data may have been exposed
Actively exploited vulnerabilities can lead to breaches of document libraries, lists, and connected systems even when ransomware use is not documented for this CVE. If you suspect exploitation, follow your incident response plan, preserve SharePoint and identity logs, and complete forensics triage consistent with CISA’s referenced requirements. As a simple personal check, you can run a free exposure scan of your email address against known breach datasets to see whether your credentials or related identities already appear in public breach collections, then force resets and session revocation where appropriate.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H