CISA KEV Alert 25 Sept 2026, 16:02 UTC

CISA Warns of Actively Exploited Microsoft SharePoint Code Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities (KEV) catalogue on 25 September 2026. The vulnerability affects Microsoft SharePoint and is identified as the Microsoft SharePoint Code Injection Vulnerability. It could allow an authorised attacker to execute code over a network.

The flaw is a code injection vulnerability in SharePoint. A network-based attacker with authorisation could exploit it to execute code on an affected system. The vulnerability has a CVSS score of 8.8 and is rated High. Microsoft has made a patch available through its security advisory.

The KEV listing confirms active exploitation in the wild. The available data does not confirm use in ransomware campaigns. CISA set 28 September 2026 as the remediation deadline for affected federal agencies.

CISA requires organisations to apply mitigations in accordance with Microsoft’s instructions, while complying with its BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Organisations must assess each asset’s internet exposure and follow applicable BOD 26-04 patching guidance for cloud services, or discontinue use where mitigations are unavailable.

Federal Civilian Executive Branch (FCEB) agencies are directly affected by this requirement, but all organisations should review their exposure and apply the available update.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline