Skip to content

A mis-rated SharePoint bug turns out to be RCE, and the patch deadline is today

CVE-2026-65660 was filed as a spoofing issue at CVSS 6.5. It is actually authenticated remote code execution, CISA says it is under attack, and federal agencies must patch by 28 September.

Source: CISA

Microsoft patched CVE-2026-65660 in its August 2026 update and filed it as a medium-severity spoofing bug, CVSS 6.5. Researchers at Viettel Cyber Security worked out that the same code-injection flaw, in SharePoint’s SafeControls validation, actually chains into authenticated remote code execution. CISA has now rated it CVSS 8.8, added it to the Known Exploited Vulnerabilities catalogue on 25 September, and set a remediation deadline of 28 September for federal civilian agencies.

It affects on-premises SharePoint Server 2016, 2019 and Subscription Edition. SharePoint Online is not affected. Exploitation needs a valid low-privileged account rather than anonymous access, though CISA’s listing confirms attackers are already using it in the wild, six weeks after the patch went out with the wrong severity attached.

Why it matters: if you run SharePoint Server on-prem, the August patch you may have deprioritised as a “spoofing fix” is actually closing an RCE path. Check you’re on the August build or later, and treat any SharePoint box with anonymous or loosely-scoped accounts as higher risk in the meantime.

The caveat: the federal deadline only binds US civilian agencies, but CISA’s KEV listing is a reliable signal that exploitation is real, not theoretical, for anyone else running the same versions.

Share

More from The Wire

All briefs