SharePoint Code Injection CVE-2026-65660 Added to KEV
CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25, 2026. Federal civilian agencies have until September 28 to patch under BOD 26-04.
What the flaw is
CVE-2026-65660 is a code injection vulnerability in Microsoft Office SharePoint (CVSS 8.8, high). An authorized attacker can trigger remote code execution over a network through the affected code path.
Microsoft originally classified the flaw as a spoofing issue, then updated the advisory to code injection as exploitation evidence accumulated. As of September 25, Microsoft confirmed “reliable evidence of observed attacks” without disclosing attacker identity, victim count, or post-exploitation activity.
CVSS 8.8 reflects that network authentication is required, which keeps it just below critical. Active exploitation is confirmed regardless.
What to do
Apply the patch. Check the MSRC advisory for CVE-2026-65660 for the specific affected SharePoint builds and update packages.
If patching this weekend is not possible, review authentication controls on your SharePoint deployment and watch for unexpected remote execution activity. Internet-facing SharePoint instances carry the highest exposure. Internal instances where attacker accounts may already exist are the next tier down.
This is not a “wait for the next Patch Tuesday” situation. Exploitation is active.
Context
This is CISA’s second round of KEV additions this week for widely deployed on-premises software. WSO2 API Manager and Adobe Commerce landed in the catalog on September 25 with the same deadline. CISA also added MikroTik RouterOS CVE-2026-67279 to the catalog at the same time, a separate router flaw with its own fix path.
See the CISA KEV catalog for the full current list. The Zyxel and Veeam additions from last week follow the same pattern of short federal remediation windows.
- [ HIGH ]CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability
Found this useful? Share it.


