## Overview
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities (KEV) catalog on September 25, 2026. This decision highlights the urgency for federal agencies to address this vulnerability by a specified deadline. The vulnerability allows an authorized attacker to execute code over a network, posing significant risks to organizations using Microsoft SharePoint.
## Technical Details
CVE-2026-65660 is categorized as a code injection vulnerability. It arises from improper control of code generation in Microsoft Office SharePoint. Attackers with valid credentials can exploit this flaw to run arbitrary code, potentially leading to unauthorized access and data manipulation. The CVSS score of 8.8 indicates a high severity level, emphasizing the critical nature of this vulnerability.
## Impact
Exploitation of CVE-2026-65660 can lead to severe consequences for affected organizations. Attackers can execute malicious code, which may result in data breaches, system compromise, or service disruptions. Given the widespread use of SharePoint in various sectors, including government and enterprise, the potential impact is broad and significant.
## Mitigation
Defenders should prioritize applying the latest security patches released by Microsoft for SharePoint. Regularly updating systems and monitoring for unusual activities can help mitigate the risks associated with this vulnerability. Organizations should also review their access controls to limit the potential for exploitation by authorized users.
CSURFACE Threat Sensor