In brief: CISA has listed CVE-2026-65660 as an actively exploited SharePoint vulnerability since 25 September 2026. Microsoft had already patched it on 11 August. The important boundary is that the flaw alone needs a low-privileged account; unauthenticated exploitation requires chaining a separate authentication bypass.
Network access, low privileges, no user interaction
Microsoft rates the code-injection flaw at CVSS 8.8. It affects SharePoint Server 2016, 2019 and Subscription Edition. The vector is AV:N/AC:L/PR:L/UI:N: network access, low privileges and no victim action. Successful exploitation can fully affect confidentiality, integrity and availability.
Microsoft's fixed build thresholds are 16.0.5565.1001 for SharePoint 2016, 16.0.10417.20198 for SharePoint 2019 and 16.0.19725.20522 for Subscription Edition. SharePoint Online is not among the products named in the CVE record.
From research detail to observed exploitation
Viettel Cyber Security described a type-check bypass in SharePoint's SafeControls processing on 22 September. Its analysis demonstrates authenticated code execution; exploitation without signing in additionally depends on a separate authentication bypass. Previdian recorded exploit attempts on 24 September and reported attempts to install a web shell the following day. Microsoft updated its assessment on 25 September with reliable evidence of attacks, and CISA added the CVE to KEV that day.
The timing does not prove that disclosure caused the attacks. It does compress the response window: US federal agencies must remediate by 28 September.
Pandorex Analysis: exposed systems need more than a patch
Operators should first compare deployed SharePoint builds with Microsoft's fixed versions and prioritise unpatched farms. Systems reachable from less-trusted networks since the technical details became public also need compromise assessment. CISA explicitly links KEV handling to forensic triage requirements; installing an update does not remove an existing web shell.
This is urgent, but it is not evidence of a universal anonymous SharePoint zero-day. The precise risk model is confirmed exploitation of an RCE patched since August that requires low login privileges, with greater exposure where attackers can chain a second authentication flaw.
