Microsoft SharePoint Server CVE-2026-65660 Actively Exploited: Critical RCE Vulnerability Threatens Unpatched Systems
A critical vulnerability affecting Microsoft SharePoint Server has been confirmed as actively exploited in the wild. The CVE-2026-65660 flaw allows authenticated, low-privileged users to execute arbitrary code remotely, and it has been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog.
The vulnerability was initially misclassified as a spoofing issue but subsequent analysis revealed it is actually a code injection flaw with severe implications for enterprise environments. Public proof-of-concept code has demonstrated the exploitation of this flaw, which can be used to deploy in-memory webshells and establish command-and-control channels.
The widespread use of Microsoft SharePoint in critical business operations, combined with the availability of public exploit code, significantly elevates the risk profile for organizations that have not yet applied the relevant security updates. Immediate action is required to mitigate this risk, including applying the Microsoft security update released on August 11, 2026.