Microsoft SharePoint CVE-2026-65660 Now Under Active Attack: Flaw First Listed as 'Spoofing' Upgraded to Code Injection RCE on CISA's KEV List

Microsoft SharePoint CVE-2026-65660 Now Under Active Attack: Flaw First Listed as 'Spoofing' Upgraded to Code Injection RCE on CISA's KEV List

Microsoft SharePoint CVE-2026-65660 Now Under Active Attack: Flaw First Listed as 'Spoofing' Upgraded to Code Injection RCE on CISA's KEV List

CISA has added CVE-2026-65660, a code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The flaw carries a CVSS score of 8.8. What makes the case notable is how it got here: Microsoft originally described CVE-2026-65660 as a spoofing vulnerability affecting SharePoint Server, then updated its advisory to state that the flaw could be abused for remote code execution. "As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the company noted — the same day CISA added it to the KEV catalog.

Microsoft has not disclosed who is behind the exploitation, when the attacks started, how many organizations were targeted, how many attempts succeeded, or what attackers did once inside the vulnerable service. Independent telemetry shared by Previdian shows the activity is real and recent: the company detected 16 exploitation attempts against its sensors on September 24, 2026, coming from IP addresses in the United Kingdom and Israel. Because the vulnerability requires an authorized attacker, initial access likely rides on a valid account or a compromised session rather than a fully unauthenticated request — but the code injection then executes with the permissions of the SharePoint service, which is exactly what turns a farm compromise into an internal foothold.

CISA added the SharePoint flaw to the KEV catalog on Friday, September 25, alongside MikroTik RouterOS CVE-2026-67279 (CVSS 6.9), an improper enforcement of behavioral workflow flaw that allows an unauthenticated client to open a session channel and send an exec request. The MikroTik flaw is the second half of the MikroTrick chain, which we covered in detail when CERT Polska disclosed it: combined with the login-process argument injection flaw CVE-2026-86060 (already on KEV since September 11), it gives attackers full unauthenticated administrative control of exposed routers.

What Should You Do?

  1. Patch SharePoint Server on the August 2026 security update track immediately — the flaw is now confirmed exploited in the wild, and KEV listing means federal agencies and any risk-managed organization treat it as an active incident, not a routine update.
  2. Assume account abuse, not just remote attack: the flaw requires an authorized attacker, so review SharePoint service accounts and privileged farm accounts for anomalous logons, new site collection permissions and unusual web part or workflow activity.
  3. Hunt for the telltales: unexpected application pool crashes, new or modified files under SharePoint web roots, and unusual outbound connections from SharePoint servers.
  4. Segment the farm: restrict SharePoint servers' outbound access and administrative paths so a successful injection does not translate into domain-wide movement.

The WAF Angle

An "authorized attacker executes code" flaw is the hardest kind for a WAF to stop: the malicious request carries a valid session, valid CSRF tokens and normal-looking traffic, so signature matching has almost nothing to grip. That is why the advisory drift from "spoofing" to "code injection RCE" matters — severity labels lag behind attack reality, and defenders who triage by vendor CVSS text alone deprioritized this for weeks. This is also the second actively exploited SharePoint RCE story of the quarter: in August, a SharePoint RCE chain was exploited as public PoCs emerged under different CVEs. For WAF operators the practical moves are behavioral: rate-limit and inspect requests that touch workflow, form and upload endpoints under privileged accounts, and alert on authenticated users whose sessions suddenly issue administrative API calls they never made before. The patch is the fix; the WAF is the seatbelt while you drive there.

Sources