Junglewise Threat Intelligence

CVE-2026-65660: Microsoft SharePoint code injection

CVE-2026-65660 · Severity: critical · Exploited in the wild · Published 2026-09-25

Executive brief

Microsoft SharePoint, an enterprise collaboration and document management platform, contains a code injection flaw that allows authenticated attackers to execute arbitrary code on the server over the network. Exploitation could lead to complete system compromise, data theft, and operational disruption across an organization's document and collaboration infrastructure.

Technical details

This vulnerability is a code injection issue in Microsoft SharePoint that permits an authenticated attacker with network access to inject and execute malicious code on the affected server. The vulnerability requires valid credentials but no user interaction. An attacker exploiting this flaw can achieve remote code execution (RCE) with the privileges of the SharePoint application. The flaw has been confirmed as exploited in the wild. Patch availability and detailed remediation guidance should be obtained from Microsoft's security advisory.

Affected products

  • Microsoft SharePoint

Timeline

  • 2026-09-25: disclosed
  • exploited: confirmed exploited in the wild

Related threats