CiberLATAMbywhalemate

CISA adds SharePoint CVE-2026-65660 to KEV

CISA added CVE-2026-65660 to the KEV catalog after active exploitation was reported. Microsoft has already released patches.

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog after September 25 reporting said the flaw was being actively exploited in Microsoft SharePoint Server 2016, 2019 and Subscription Edition, along with another MikroTik RouterOS vulnerability.

CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities, or KEV, catalog after September 25 reports said the flaw was being actively exploited in Microsoft SharePoint Server 2016, 2019 and Subscription Edition. The issue was described as a code injection vulnerability, and according to multiple sources, Microsoft had already released patches.

What did CISA do with CVE-2026-65660?

CISA added the flaw to its KEV catalog, a sign the agency considers it to be exploited in practice. The Hacker News reported the inclusion on September 25, 2026, while BleepingComputer said the SharePoint vulnerability was being actively exploited in the wild alongside another MikroTik RouterOS flaw.

Available coverage also says CISA set a federal remediation deadline of September 28, 2026. Security Affairs also noted that the exploitation scenario requires authenticated access with low privileges and the ability to execute code remotely, which rules out a fully unauthenticated exploitation path.

What is known about the SharePoint flaw?

The flaw affects SharePoint Server 2016, 2019 and Subscription Edition, and it was described as a code injection vulnerability. ThaiCERT reported on September 23 that Microsoft had reclassified it from spoofing to remote code execution and had already released updates to fix it.

A technical analysis cited by The Cyber Express linked it to a broken SafeControls validation process. According to that report, unescaped quotes in web part markup processing can allow Register directives to be introduced and arbitrary .NET classes to be triggered through deserialization with XamlServices.Parse(). Decryption Digest described a similar mechanism centered on the ToolPane component and the ability to register .NET classes outside the SafeControls filter, leading to remote code execution.

What patches and fixed versions were reported?

The Canadian Centre for Cyber Security, in its AL26-023 advisory cited by Provintell, listed fixed versions for the affected editions. For SharePoint Enterprise Server 2016, it cited build 16.0.5565.1001. For SharePoint Server 2019, it cited 16.0.10417.20198. For SharePoint Server Subscription Edition, it cited 16.0.19725.20522.

The Cyber Express added that the vulnerability had a base CVSS score of 8.8 and listed related fixes tied to KB 5002893 for Subscription Edition, KB 5002894 and KB 5002896 for SharePoint 2019, and KB 5002905 and KB 5002906 for SharePoint 2016. CISA's decision to include it in the KEV was based on that mix of official alerts and technical analysis.

Sources

View all