Skip to content
feed: live
>_0dayNews
cisa kev
● Breaking

SharePoint Code Injection CVE-2026-65660 Added to KEV

CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

SharePoint Code Injection CVE-2026-65660 Added to KEV
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25, 2026. Federal civilian agencies have until September 28 to patch under BOD 26-04.

What the flaw is

CVE-2026-65660 is a code injection vulnerability in Microsoft Office SharePoint (CVSS 8.8, high). An authorized attacker can trigger remote code execution over a network through the affected code path.

Microsoft originally classified the flaw as a spoofing issue, then updated the advisory to code injection as exploitation evidence accumulated. As of September 25, Microsoft confirmed “reliable evidence of observed attacks” without disclosing attacker identity, victim count, or post-exploitation activity.

CVSS 8.8 reflects that network authentication is required, which keeps it just below critical. Active exploitation is confirmed regardless.

What to do

Apply the patch. Check the MSRC advisory for CVE-2026-65660 for the specific affected SharePoint builds and update packages.

If patching this weekend is not possible, review authentication controls on your SharePoint deployment and watch for unexpected remote execution activity. Internet-facing SharePoint instances carry the highest exposure. Internal instances where attacker accounts may already exist are the next tier down.

This is not a “wait for the next Patch Tuesday” situation. Exploitation is active.

Context

This is CISA’s second round of KEV additions this week for widely deployed on-premises software. WSO2 API Manager and Adobe Commerce landed in the catalog on September 25 with the same deadline. CISA also added MikroTik RouterOS CVE-2026-67279 to the catalog at the same time, a separate router flaw with its own fix path.

See the CISA KEV catalog for the full current list. The Zyxel and Veeam additions from last week follow the same pattern of short federal remediation windows.

Related CVEs
  • [ HIGH ]CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability

Found this useful? Share it.