CVE-2026-65660
sharepoint_server: Improper Control of Generation of Code ('Code Injection') (CVE-2026-65660)
Affected
- microsoft/sharepoint_server
lt *..16.0.19725.20522
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-65660 carries a CVSS score of 8.8 with the vector AV:N/AC:L/PR:L/UI:N, meaning it is exploitable over the network with low complexity and requires only a standard authenticated user — no administrator account needed. In organisations where SharePoint is broadly deployed as an intranet or collaboration platform with many users holding Contribute rights, the effective attack surface is very large. The EPSS score of 1.19 % (66th percentile) reflects elevated but not yet mass-exploitation risk; however, CISA KEV inclusion confirms active exploitation in the wild, which elevates patch priority to critical regardless of EPSS. NIS2-scoped KRITIS organisations should treat this as a high-severity finding: SharePoint commonly holds sensitive documents and business-process data, and successful exploitation yields full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) on the affected host, with realistic paths to broader domain compromise via the service account context.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch immediately: the affected baseline version is SharePoint Server 16.0.19725.20522. Retrieve the exact patch ID and download link from the current Microsoft Security Response Center (MSRC) advisory and deploy it across all SharePoint farms without delay.
- Isolate any internet-facing or reverse-proxy-exposed SharePoint farms, or enforce an additional authentication layer (e.g. Azure AD Application Proxy with MFA) in front of them until the patch is confirmed deployed.
- Treat all SharePoint service accounts (Farm Account, App Pool identities, Search Service Account) as potentially compromised: rotate passwords immediately, purge Kerberos tickets (
klist purgeon affected servers), and evaluate whether a krbtgt reset is warranted. - Restrict inbound HTTP/HTTPS traffic (port 443, optionally 80) to SharePoint servers at the WAF or reverse proxy layer — temporarily allowlist only known source ranges and alert on POST requests to
/_layouts/,/_api/, and/_vti_bin/endpoints. - Audit local administrator memberships on all SharePoint servers: only Farm Administrator accounts should hold local admin rights; remove all others immediately.
Runbook · Step 2
Mitigation layers
- Network segmentation: Place SharePoint servers in a dedicated VLAN and block outbound connections from those servers to the internet and to Tier-0 assets (Domain Controllers, PKI) — this limits lateral movement if code injection succeeds.
- WAF/IPS rule: Deploy a Snort/Suricata signature targeting suspicious POST payloads on SharePoint endpoints:
alert http any any -> $SHAREPOINT_SERVERS 443 (msg:"CVE-2026-65660 SharePoint Code Injection attempt"; content:"POST"; http_method; content:"/_layouts/"; http_uri; pcre:"/(<script|eval\(|System\.Reflection|Assembly\.Load)/i"; sid:9266560; rev:1;). - Least privilege / IAM: Audit SharePoint user permissions and remove unnecessary Contribute and Design rights — because the vulnerability requires only a low-privileged authenticated user (PR:L), reducing the population of users with write access directly shrinks the attack surface.
- Endpoint hardening: Enable AppLocker or Windows Defender Application Control (WDAC) on SharePoint servers to prevent the IIS worker process (
w3wp.exe) from spawning unsigned binaries or executing arbitrary PowerShell. - Configuration change: Disable SharePoint Solution Deployment and Farm Feature Activation on production systems unless operationally required — these are common code-injection vectors that should not be available in a hardened production farm.
Runbook · Step 3
Detection rules
- Windows Security Event ID 4688: Monitor for process creation on SharePoint servers where the parent process is
w3wp.exeand the child iscmd.exe,powershell.exe,csc.exe, ormsbuild.exe— a strong indicator of successful code injection. KQL:SecurityEvent | where EventID == 4688 and ParentProcessName has "w3wp.exe" and NewProcessName has_any ("cmd.exe","powershell.exe","csc.exe","msbuild.exe"). - Sysmon EID 1 / EID 3: Alert on process creation by
w3wp.exewith unusual command-line arguments, and on outbound network connections fromw3wp.exeto external IPs (Sysmon EID 3) — neither should occur in normal SharePoint operation. - IIS access logs / web telemetry: Flag HTTP POST requests returning status 200 to
/_layouts/15/,/_api/web/, or/_vti_bin/with unusually large request bodies (> 50 KB) or Base64-encoded content in the body. SPL:index=iis cs_method=POST cs_uri_stem="*/_layouts/*" sc_status=200 cs_bytes>51200. - Sigma rule (shape):
title: SharePoint w3wp Child Process/logsource: category: process_creation, product: windows/detection: selection: ParentImage|endswith: '\w3wp.exe', Image|endswith: ['\cmd.exe','\powershell.exe','\csc.exe'] / condition: selection. - EDR telemetry: File-write events by
w3wp.exeoutside the SharePoint hive (C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\) — writes to%TEMP%,%APPDATA%, orC:\Windows\Tempare strong indicators of dropper activity following successful exploitation.
Description
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
16.0.19725.20522fixed from 16.0.19725.20522Metrics
Show all metrics
Weakness classes (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660vendor-advisorypatch
- https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660government-resource
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-26 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- Modified Analysis2026-09-25 17:00 UTC· nvd@nist.gov
- Reference Type: CISA-ADP: https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/ Types: Third Party Advisory
- Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660 Types: US Government Resource
- CVE Modified2026-09-25 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://blog.previdian.com/cve-2026-65660-previdian-observes-two-stage-sharepoint-exploitation-attempts/
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65660
- SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technica…
- CVE CISA KEV Update2026-09-25 16:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-09-25
- Due Date: 2026-09-25
- Required Action: 2026-09-25
- Vulnerability Name: 2026-09-25
- CVE Modified2026-09-25 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- SSVC: {"id":"CVE-2026-65660","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
Linked advisories
- securityweek2026-09-27 09:23 UTCMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
- thehackernews2026-09-26 08:49 UTCSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- thehackernews2026-09-22 11:17 UTCSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
- ncsc-nl2026-08-27 10:23 UTCNCSC-2026-0286 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Office
- sans-atrisk-mail2026-08-13 00:00 UTC@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 31