CISA Adds Microsoft SharePoint Spoofing Vulnerability
CVE-2026-65660, rated 6.5 by Microsoft in August, is actively exploited remote code execution. CISA has given federal agencies until September 28 to patch it.

On September 25, CISA, the U.S. government's cybersecurity agency, added CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server, to its Catalog of Actively Exploited Vulnerabilities (KEV). Reports indicate that federal civilian agencies have until Monday, September 28, to implement the patch.
The same update included CVE-2026-67279, affecting MikroTik’s RouterOS. Both entries target equipment typically operated by companies on their own infrastructure, outside of the vendor-managed cloud.
Originally Spoofing, Now Remote Code Execution
What interests the CISO is the original classification. When Microsoft released security updates on August 11, CVE-2026-65660 was listed as a spoofing vulnerability with a CVSS score of 6.5, deemed moderate. According to The Hacker News and Petri reports, Microsoft updated the CVE record on September 11, now describing the vulnerability as remote code execution by an authenticated attacker. The NVD, maintained by NIST, assigns a score of 8.8, categorizing it as high.
This difference impacts the patching priority. Teams that prioritize patches based on vendor ratings and bulletin categories had valid reasons in August to postpone this correction behind those classified as critical. The patch has been available for 45 days; only the label has changed.
The vulnerability affects SharePoint Server 2016, 2019, and the Subscription Edition, all of which are installed locally. According to technical analyses published after the KEV inclusion, the issue lies in the validation of the SafeControls list, the filter that prevents loading dangerous classes: the ToolPane component reconstructs directives without escaping quotes, allowing an authenticated user with limited privileges to register arbitrary .NET classes and execute code on the server.
From Low Privilege Account to Passwordless Attack
Alone, the vulnerability requires a valid account. The risk escalates when chained. According to intelligence firm Previdian, mentioned in multiple technical reports, attempts have been observed exploiting CVE-2026-65660 in conjunction with a separate bug for anonymous delivery, to install an encrypted loader and take control of the server. In installations configured to accept anonymous access, this chain results in remote code execution without authentication.
This pattern is already known in the market for on-premises SharePoint systems. In July, CISA had added another remote execution vulnerability in the product, CVE-2026-45659, according to The Hacker News. Two entries in two months for the same server indicate that attackers view on-premises SharePoint as a recurring target.
Three Countries, Three Signals
The reading of this situation extends beyond Washington. The September 28 deadline applies only to U.S. federal agencies, but the standard language of CISA alerts recommends that all organizations, public and private, prioritize patching vulnerabilities in the catalog. For government vendors, an entry in KEV with a three-day deadline turns into an audit question the following week.
In Canada, the Canadian Centre for Cyber Security published alert AL26-023 dedicated to CVE-2026-65660. A national alert dedicated to a single CVE signals that the agency considers the exposure relevant for Canadian operators, thus providing local guidance, not just echoing Washington.
In Poland, the signal comes from the other half of the update. CERT Polska confirmed that the RouterOS vulnerability has been actively exploited against internet-exposed devices since at least September 2. According to technical reports, chained to CVE-2026-86060 in the so-called MikroTrick chain, it grants administrative access without authentication. Documented attacks by CERT Polska began 23 days prior to the inclusion in the American catalog, during which time CISA's list served as no alert to anyone.
What the Catalog Doesn’t Say
There is a caveat. CISA includes a vulnerability in KEV based on evidence of exploitation, but the catalog does not inform about attack volume, affected sectors, or victims. As of the publication of this article, no organization had been publicly identified as a victim of CVE-2026-65660.
For those managing a local setup, the practical information is the patch date, not the catalog inclusion date. The August 11 package (KB5002893, for the Subscription Edition) already addresses the vulnerability. Those who implemented the updates that month are protected; those who postponed due to the initial 6.5 rating discovered this week that the initial classification underestimated the risk.
Sources
- cisa.govhttps://www.cisa.gov/news-events/alerts/2026/09/25/cisa-adds-two-known-exploited-vulnerabilities-catalog
- msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-65660
- thehackernews.comhttps://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
- petri.comhttps://petri.com/sharepoint-validation-flaw-remote-code-execution/
- cyber.gc.cahttps://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660
- securityaffairs.comhttps://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html
- support.microsoft.comhttps://support.microsoft.com/en-us/servicing/office/hotfix/august/5002893