A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is being exploited in attacks, around six weeks after Microsoft released patches and days after researchers published technical details. Microsoft fixed the issue in its August 2026 Patch Tuesday updates and describes it as a code-injection flaw that allows an authenticated attacker with low-level access to an affected server to execute arbitrary code without user interaction. In an advisory update, Microsoft said it had “reliable evidence” of observed exploitation as of 25 September 2026.
Previdian, an early-warning threat intelligence company, reported exploitation attempts on 24 September and attempts to create a webshell backdoor the following day. The activity appears to have begun shortly after Viettel Security disclosed technical information about the vulnerability, although the attackers’ identity is unknown. Previdian said the observed exploits appeared to be based on Viettel’s disclosure.
The flaw is a type-check bypass that produces code execution for an authenticated attacker; unauthenticated remote code execution requires chaining it with a separate authentication-bypass weakness. CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalogue on 25 September, setting a 28 September patching deadline for US federal agencies. SharePoint administrators should apply Microsoft’s available updates, with the urgency reinforced by confirmed exploitation and reported webshell activity.