A significant vulnerability in Microsoft SharePoint, identified as CVE-2026-65660, is currently being actively exploited in cyberattacks. This development comes just six weeks after Microsoft issued patches and only days after researchers released detailed technical information about the flaw. The vulnerability is classified as a remote code execution issue that allows an authenticated attacker with low-level access to execute arbitrary code on affected servers without user interaction.

Microsoft updated its advisory on September 25, 2026, confirming observed attacks targeting this vulnerability. In response, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65660 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch the flaw by September 28.

Previdian, an early-warning threat intelligence platform, recorded attempts to exploit this vulnerability on September 24, with subsequent efforts to deploy a webshell backdoor. The exact perpetrators of these attacks remain unknown, but the exploitation began soon after Viettel Security, the entity that reported the vulnerability to Microsoft, disclosed its technical details.

Initially, Microsoft categorized the flaw as a medium-severity spoofing issue but later reclassified it as a high-severity remote code execution vulnerability. The flaw requires low-level privileges and authenticated access, although unauthenticated remote code execution could be achieved by combining it with other vulnerabilities. Previdian observed that the exploits in the wild appear to leverage the information provided by Viettel.

There are currently sixteen SharePoint vulnerabilities listed in CISA's KEV catalog, eight of which were discovered and patched this year.