← Blog · · df00tech

CVE-2026-65660: Actively Exploited Code Injection Flaw in Microsoft SharePoint Added to CISA KEV

breaking kev Microsoft CVE-2026-65660

CISA has added CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed in-the-wild exploitation. According to Microsoft's advisory, the flaw allows an authorized attacker to execute code over a network. A CVSS score has not yet been published, and Microsoft has not disclosed the specific attack vector, patch status, or details of observed exploitation at this time.

Why It Matters

SharePoint is widely deployed across enterprise and government environments as a document management and collaboration platform, often exposed to the internet or accessible to large numbers of internal users. Code injection vulnerabilities in SharePoint have historically been attractive targets for both opportunistic and targeted actors because successful exploitation can lead to remote code execution on the server, potentially exposing sensitive documents, credentials, and lateral movement paths into the broader network. The "authorized attacker" language suggests some level of authentication or access may be a prerequisite, but this does not diminish the urgency — authenticated RCE flaws in SharePoint have repeatedly been chained with other issues or exploited via compromised low-privilege accounts.

What Defenders Should Do Now

  • Identify all internet-facing and internal SharePoint Server instances in your environment and confirm current patch levels.
  • Monitor Microsoft's advisory and CISA's KEV entry for updates on affected versions and remediation guidance as they are published.
  • Review SharePoint application logs and IIS/W3C logs for anomalous requests, unexpected process spawning from the SharePoint application pool (e.g., w3wp.exe spawning cmd.exe or powershell.exe), and unusual file writes to web-accessible directories.
  • Audit authentication and authorization events for SharePoint accounts, since exploitation appears to require some form of authorized access.
  • Ensure endpoint detection is active on SharePoint servers and that outbound network connections from these hosts are monitored for signs of post-exploitation activity.
  • Follow CISA KEV remediation timelines if your organization is a federal civilian agency subject to Binding Operational Directive requirements, and treat this as high priority regardless of sector given active exploitation.

This is a developing situation with limited public technical detail at the time of writing. df00tech will publish a dedicated detection rule and update this analysis as Microsoft and CISA release further guidance. For the authoritative advisory, see Microsoft's MSRC entry for CVE-2026-65660.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.