CVE-2026-65660

HIGH CISA KEV POC Pub 11/08 Upd 26/09

Overview

This vulnerability is a code injection flaw arising from improper control over code generation within Microsoft Office SharePoint Server 2016. The root cause lies in insufficient validation and sanitization of user-supplied input that is processed in SharePoint's code generation mechanisms. The affected component is the SharePoint Enterprise Server 2016 platform, specifically in its handling of input that influences dynamic code execution.

Vulnerability Description

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Impact

An attacker with a low-privileged authenticated account can exploit this vulnerability to execute arbitrary code remotely on the SharePoint server. This enables full compromise of the affected system, including unauthorized access to sensitive data, modification of content, and potential lateral movement within the network. The business impact includes data breaches, disruption of SharePoint services, and loss of system integrity.

Solution

Microsoft has released security updates addressing this vulnerability in SharePoint Server 2016 and 2019. Administrators should apply the latest patches as detailed in the Microsoft Security Response Center advisory available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660. The advisory provides specific update versions and installation instructions to remediate the issue effectively.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products (3)

Vendor Product Version CPE
microsoft Microsoft Sharepoint Server All cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
microsoft Microsoft Sharepoint Server 2016 cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
microsoft Microsoft Sharepoint Server 2019 cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (2)

Repository Author Stars Forks Date Link
ShadowForge-Cyber/CVE-2026-65660-Poc
Malicious Register Directive Code Injection Exploit
ShadowForge-Cyber 1 0 2026-09-25 View
HORKimhab/CVE-2026-65660
CVE-2026-65660 - Draft or TODO
HORKimhab 0 0 2026-09-25 View
Exploited in Wild CONFIRMED
Ransomware IN USE
Attacker Interest VERY HIGH
Sightings Some sightings

Threat Feed

13 events
2026-09-26
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-26
Exploited by thegentlemen

Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)

2026-09-26
Exploited by bianlian

Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AmmyyAdmin, AnyDesk, Atera (552 known victims)

2026-09-26
Exploited by blackbasta

Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)

2026-09-26
Exploited by bian lian

Ransomware group known to exploit this vulnerability

2026-09-26
Exploited by Magic Hound

Ransomware group known to exploit this vulnerability

2026-09-25
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-25
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-09-25
PoC Published (2 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2026-09-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-09-22
Threat Sensor Sighting — Some sightings

Sighting activity recorded

Detected as Exploited in the Wild (18 sightings)

Active exploitation confirmed with 18 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Remote Code Execution
100% rce
Code Injection
80% code_injection
Insecure Direct Object Reference
62% idor

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-242 Code Injection
51%
High High
CAPEC-35 Leverage Executable Code in Non-Executable Files
41%
High Very High
CAPEC-77 Manipulating User-Controlled Variables
35%
High Very High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-65660
msrc.microsoft.com
GitHub CVE vendor-advisory patch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
blog.previdian.com
NVD API Third Party Advisory
https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660