Skip to main content

SharePoint Server Under Active Exploitation: CVE-2026-65660 Enables Code Execution on Local Servers

CISA has confirmed the active exploitation of CVE-2026-65660, a code injection vulnerability in on-premise SharePoint Server released by Microsoft in August. It impacts SharePoint 2016, 2019, and Subscription Edition, the first two of which are already out of support.

CybersecuritySeintec team3 min read
SharePoint Server Under Active Exploitation: CVE-2026-65660 Enables Code Execution on Local Servers

News summary

On 25 September 2026, CISA added CVE-2026-65660 to its KEV catalogue, a code injection flaw (CWE-94) in Microsoft SharePoint Server with a CVSS score of 8.8. The day before, the Canadian Centre for Cyber Security had issued its own alert. While the vulnerability was disclosed in August, the new development is the confirmation that it is now being used in real-world attacks.

In a direct scenario, an attacker requires a low-privileged account. However, the Canadian alert warns that it can be chained with other SharePoint vulnerabilities to achieve unauthenticated remote code execution on servers configured with anonymous access.

The minimum patched versions specified are 16.0.5565.1001 for SharePoint Enterprise Server 2016, 16.0.10417.20198 for SharePoint Server 2019, and 16.0.19725.20522 for Subscription Edition. According to the Canadian advisory, SharePoint 2016 and 2019 reached end-of-life on 15 July 2026: updating is urgent, but the fundamental response is to migrate to a supported edition.

SharePoint typically centralises internal documentation, projects, and procedures, and is connected to identities and databases. Consequently, a compromised server is not an isolated problem: it can serve as a gateway for data theft or lateral movement across the network.

Source: CiberPlaneta — 25 September 2026

Frequently Asked Questions

Does this affect Microsoft 365 SharePoint Online?
The published alerts refer to on-premise SharePoint Server installations (2016, 2019, and Subscription Edition). SharePoint Online is maintained by Microsoft.
Is it still safe to use SharePoint 2016 or 2019 after patching?
The patch addresses this specific vulnerability, but both versions have been out of support since July 2026 and will not receive regular future updates. Planning a migration is recommended.

Concepts mentioned in this article: Vulnerability

If your business maintains SharePoint on its own servers, review your versioning and exposure today. At Seintec, we update, secure, and migrate SharePoint environments to supported platforms. Contact our team.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.