News / Cybersecurity
CVE-2026-65660: Microsoft SharePoint Under Attack Despite August 2026 Patches Published on 28 September 2026 by Christ-loisele (2 min read)
The critical vulnerability CVE-2026-65660, patched since August 2026, is now being actively exploited in campaigns targeting SharePoint. Evidence of attacks, confirmed by Microsoft and the CISA, underscores the urgency for organizations to deploy updates without delay.
A critical flaw reassessed after real-world attacks
The vulnerability CVE-2026-65660 , initially classified as a medium-severity spoofing issue by Microsoft in its August 11, 2026 patch, proves far more dangerous today. According to SecurityWeek , Microsoft revised its assessment after detecting reliable signs of exploitation as early as September 25, 2026. The flaw, found in Microsoft SharePoint Server 2016, 2019, and Subscription Edition (on-premises versions), allows an authenticated attacker with low privileges to inject code and execute arbitrary commands without user interaction.
The Canadian Centre for Cyber Security notes that this vulnerability, combined with other SharePoint flaws, can even lead to pre-authentication remote code execution , a far more severe scenario. The exploited mechanism relies on a flaw in the SafeControls list management, as demonstrated by the ToolShell exploit presented at the Pwn2Own Berlin 2025 by Dinh Ho Anh Khoa.
Attacks combine CVE-2026-65660 with other SharePoint vulnerabilities to achieve unauthenticated remote code execution, according to the Canadian Centre for Cyber Security.
Photo: Microsoft (Coolcaesar, CC BY-SA 4.0)
Active exploitation: documented attacks since September 2026
Initial exploitation attempts were reported as early as September 24, 2026 by Previdian (formerly KEVIntel) , with evidence of webshells (persistent backdoors) created the following day. Microsoft confirmed these attacks on September 25, when the CISA (Cybersecurity and Infrastructure Security Agency) added the vulnerability to its KEV (Known Exploited Vulnerabilities) catalog, imposing a patch deadline of September 28, 2026 for U.S. federal agencies.
According to WindowsForum , cybercriminals appear to have used technical details disclosed by Viettel Security to develop their attacks. This vulnerability now joins the 16 SharePoint flaws already listed in the KEV, with eight discovered in 2026 alone.
What this means here
For businesses and government entities in Benin and West Africa using Microsoft SharePoint (versions 2016, 2019, or Subscription Edition on-premises), this active exploitation demands immediate action: verify and apply the August 2026 patches if not already done. Organizations relying on SharePoint for collaboration or document management must also monitor authentication logs and unusual behaviors, as attacks exploit low-privilege accounts.
Public administrations, often privileged targets for exfiltrations of sensitive data, could face increased risks if complementary vulnerabilities (such as those highlighted by the Canadian Centre for Cyber Security ) are exploited in sequence. An audit of SharePoint configurations and raising awareness of cybersecurity best practices (such as limiting privileges) would be essential preventive measures.
Sources