SharePoint Server Under Active Exploitation: CVE-2026-65660 Enables Code Execution on Local Servers
CISA has confirmed the active exploitation of CVE-2026-65660, a code injection vulnerability in on-premise SharePoint Server released by Microsoft in August. It impacts SharePoint 2016, 2019, and Subscription Edition, the first two of which are already out of support.

News summary
On 25 September 2026, CISA added CVE-2026-65660 to its KEV catalogue, a code injection flaw (CWE-94) in Microsoft SharePoint Server with a CVSS score of 8.8. The day before, the Canadian Centre for Cyber Security had issued its own alert. While the vulnerability was disclosed in August, the new development is the confirmation that it is now being used in real-world attacks.
In a direct scenario, an attacker requires a low-privileged account. However, the Canadian alert warns that it can be chained with other SharePoint vulnerabilities to achieve unauthenticated remote code execution on servers configured with anonymous access.
The minimum patched versions specified are 16.0.5565.1001 for SharePoint Enterprise Server 2016, 16.0.10417.20198 for SharePoint Server 2019, and 16.0.19725.20522 for Subscription Edition. According to the Canadian advisory, SharePoint 2016 and 2019 reached end-of-life on 15 July 2026: updating is urgent, but the fundamental response is to migrate to a supported edition.
SharePoint typically centralises internal documentation, projects, and procedures, and is connected to identities and databases. Consequently, a compromised server is not an isolated problem: it can serve as a gateway for data theft or lateral movement across the network.
Source: CiberPlaneta — 25 September 2026
Frequently Asked Questions
- Does this affect Microsoft 365 SharePoint Online?
- The published alerts refer to on-premise SharePoint Server installations (2016, 2019, and Subscription Edition). SharePoint Online is maintained by Microsoft.
- Is it still safe to use SharePoint 2016 or 2019 after patching?
- The patch addresses this specific vulnerability, but both versions have been out of support since July 2026 and will not receive regular future updates. Planning a migration is recommended.
Concepts mentioned in this article: Vulnerability
If your business maintains SharePoint on its own servers, review your versioning and exposure today. At Seintec, we update, secure, and migrate SharePoint environments to supported platforms. Contact our team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.