Microsoft Misclassifies Critical SharePoint Vulnerability as Spoofing Flaw
A SharePoint Server vulnerability that was initially misclassified as a spoofing flaw by Microsoft has been found to enable authenticated remote code execution, according to research by Viettel Cyber Security.
The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition, and is rated 8.8 on the National Vulnerability Database. Patches were available since August 11's security updates, but Microsoft initially described the vulnerability as allowing authorized attackers to perform spoofing with no impact to integrity or availability.
However, researcher Dinh Ho Anh Khoa demonstrated that the flaw can be exploited for remote code execution through deserialization, and even chained with a separate authentication bypass to reach pre-authentication RCE on servers configured to allow anonymous page access. The vulnerability affects SharePoint 2013 as well, although Microsoft's advisory only listed the three aforementioned versions.