CVE-2026-65660
Overview
This vulnerability is a code injection flaw arising from improper control over code generation within Microsoft Office SharePoint Server 2016. The root cause lies in insufficient validation and sanitization of user-supplied input that is processed in SharePoint's code generation mechanisms. The affected component is the SharePoint Enterprise Server 2016 platform, specifically in its handling of input that influences dynamic code execution.
Vulnerability Description
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Impact
An attacker with a low-privileged authenticated account can exploit this vulnerability to execute arbitrary code remotely on the SharePoint server. This enables full compromise of the affected system, including unauthorized access to sensitive data, modification of content, and potential lateral movement within the network. The business impact includes data breaches, disruption of SharePoint services, and loss of system integrity.
Solution
Microsoft has released security updates addressing this vulnerability in SharePoint Server 2016 and 2019. Administrators should apply the latest patches as detailed in the Microsoft Security Response Center advisory available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660. The advisory provides specific update versions and installation instructions to remediate the issue effectively.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Microsoft | Sharepoint Server | All |
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
|
|
|
Microsoft | Sharepoint Server | 2016 |
cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
|
|
|
Microsoft | Sharepoint Server | 2019 |
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ShadowForge-Cyber/CVE-2026-65660-Poc
Malicious Register Directive Code Injection Exploit
|
ShadowForge-Cyber | 1 | 0 | 2026-09-25 | View |
|
HORKimhab/CVE-2026-65660
CVE-2026-65660 - Draft or TODO
|
HORKimhab | 0 | 0 | 2026-09-25 | View |
Threat Feed
13 eventsSighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AmmyyAdmin, AnyDesk, Atera (552 known victims)
Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Active exploitation confirmed with 18 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-65660 |
| msrc.microsoft.com |
GitHub CVE
vendor-advisory
patch
|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660 |
| blog.previdian.com |
NVD API
Third Party Advisory
|
https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660 |