Skip to content
Back to Guavy Wire
Stocks

Microsoft Misclassifies Critical SharePoint Vulnerability as Spoofing Flaw

Instruments
MSFT
Share

A SharePoint Server vulnerability that was initially misclassified as a spoofing flaw by Microsoft has been found to enable authenticated remote code execution, according to research by Viettel Cyber Security.

The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition, and is rated 8.8 on the National Vulnerability Database. Patches were available since August 11's security updates, but Microsoft initially described the vulnerability as allowing authorized attackers to perform spoofing with no impact to integrity or availability.

However, researcher Dinh Ho Anh Khoa demonstrated that the flaw can be exploited for remote code execution through deserialization, and even chained with a separate authentication bypass to reach pre-authentication RCE on servers configured to allow anonymous page access. The vulnerability affects SharePoint 2013 as well, although Microsoft's advisory only listed the three aforementioned versions.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc