1. Home
  2. Security Advisories

Microsoft SharePoint Server Vulnerability: CVE-2026-65660 Is Being Exploited

Security advisory High 4 min read

This article is also available in: TürkçeDeutsch

Microsoft SharePoint Server Vulnerability: CVE-2026-65660 Is Being Exploited
CVECVE-2026-65660
SeverityHigh
CVSS score 8.8
StatusPatch available
Affected productsOn-premises SharePoint Server 2016, 2019, and Subscription Edition. SharePoint Online is not named as affected in these advisories.

CVE-2026-65660 lets an authenticated attacker inject and run code on on-premises Microsoft SharePoint Server. The score is CVSS 8.8 under CVSS 3.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability was published on 11 August 2026, and the fix was announced…

Summary

CVE-2026-65660 lets an authenticated attacker inject and run code on on-premises Microsoft SharePoint Server. The score is CVSS 8.8 under CVSS 3.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability was published on 11 August 2026, and the fix was announced then. This bulletin is about confirmed exploitation, not a new patch.

CISA added the flaw to the Known Exploited Vulnerabilities (KEV) catalog on 25 September 2026. The due date for US federal agencies was 28 September 2026. SecurityWeek, on 27 September 2026, quotes Microsoft as saying that as of 25 September 2026 Microsoft had reliable evidence of observed attacks.

This issue is not the Windows zero-days CVE-2026-81963 and CVE-2026-85880, which were covered in an earlier bulletin.

  • Affected products: SharePoint Server 2016, 2019, and Subscription Edition (on-premises).
  • Authentication: On its own, the attacker must already be signed in (PR:L in the CVSS vector).
  • Chain: Combined with an older authentication bypass, pre-authentication remote code execution is possible on servers that still allow anonymous access. The Canadian Centre for Cyber Security says that bypass path is closed by the updates of 9 June 2026. The bypass CVE number is not in the source summary we are using, so it is not stated here.
  • Support: The same centre says SharePoint Server 2016 and 2019 reached end of life on 15 July 2026.

What it is

The flaw allows an attacker who can sign in to inject and run code on SharePoint Server. It is reachable over the network, with low attack complexity and no user interaction. Confidentiality, integrity, and availability are all scored high.

Because the fix was published on 11 August 2026, the patch itself is not new. Addition to the KEV catalog on 25 September 2026, and Microsoft's evidence of observed attacks as of that date, is the reason to check whether a server is still behind the fixed build.

Chained with the older authentication bypass, code execution without a sign-in can be possible on servers that still allow anonymous access. The Canadian Centre for Cyber Security says that path is closed by the 9 June 2026 updates. Servers that missed those updates and still allow anonymous access carry the wider risk described in the advisory.

Who is affected

The affected products are on-premises SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Servers below the fixed builds below are affected.

SharePoint Online and Microsoft 365 are not named as affected products in these advisories. That sentence only restates the scope of the advisories. It does not mean Online has been shown to be safe beyond that.

Fixed build numbers are listed below for 2016 and 2019 as well. The Canadian Centre for Cyber Security still states that those two releases reached end of life on 15 July 2026. Continuing to run an end-of-life product is a separate risk from this single flaw.

Affected versions

ProductFixed build
SharePoint Server 201616.0.5565.1001
SharePoint Server 201916.0.10417.20198
SharePoint Server Subscription Edition16.0.19725.20522

What to do

  1. Read the build on the on-premises server. If you run 2016, 2019, or Subscription Edition, compare the running build with the table. Servers below that number are unfixed for this issue.
  2. Move to the fixed build. That is 16.0.5565.1001 for 2016, 16.0.10417.20198 for 2019, and 16.0.19725.20522 for Subscription Edition. Do not wait for a new patch. The fix has been available since 11 August 2026; what is new is exploitation.
  3. Check anonymous access and the June 2026 updates. On servers that still allow anonymous access and did not receive the 9 June 2026 updates, the sources also describe a pre-authentication code-execution path chained with the older authentication bypass. The Canadian centre says that path is closed by those updates.
  4. Plan for the end-of-life releases. According to the Canadian Centre for Cyber Security, 2016 and 2019 reached end of life on 15 July 2026. Apply the builds given for this flaw, and plan a move to a supported release separately.
  5. Do not put SharePoint Online on this patch list. Online is not named as affected in these advisories. If you have an on-premises server, the check is against the on-premises build.

How Doğa Network can help

Our team can help with an on-premises SharePoint build check, the move to the fixed build, and a review of anonymous access. Call +90 850 888 3642 or email hi@doga.network.

Sources

#SharePoint#Microsoft#CVE-2026-65660
Newsletter

Hear about critical vulnerabilities first.

Get our security advisories, practical guides and announcements by email. A few emails a month, no advertising.

Which topics would you like to hear about?