CISA adds SharePoint CVE-2026-65660 to KEV
CISA added CVE-2026-65660 to the KEV catalog after active exploitation was reported. Microsoft has already released patches.
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog after September 25 reporting said the flaw was being actively exploited in Microsoft SharePoint Server 2016, 2019 and Subscription Edition, along with another MikroTik RouterOS vulnerability.
CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities, or KEV, catalog after September 25 reports said the flaw was being actively exploited in Microsoft SharePoint Server 2016, 2019 and Subscription Edition. The issue was described as a code injection vulnerability, and according to multiple sources, Microsoft had already released patches.
What did CISA do with CVE-2026-65660?
CISA added the flaw to its KEV catalog, a sign the agency considers it to be exploited in practice. The Hacker News reported the inclusion on September 25, 2026, while BleepingComputer said the SharePoint vulnerability was being actively exploited in the wild alongside another MikroTik RouterOS flaw.
Available coverage also says CISA set a federal remediation deadline of September 28, 2026. Security Affairs also noted that the exploitation scenario requires authenticated access with low privileges and the ability to execute code remotely, which rules out a fully unauthenticated exploitation path.
What is known about the SharePoint flaw?
The flaw affects SharePoint Server 2016, 2019 and Subscription Edition, and it was described as a code injection vulnerability. ThaiCERT reported on September 23 that Microsoft had reclassified it from spoofing to remote code execution and had already released updates to fix it.
A technical analysis cited by The Cyber Express linked it to a broken SafeControls validation process. According to that report, unescaped quotes in web part markup processing can allow Register directives to be introduced and arbitrary .NET classes to be triggered through deserialization with XamlServices.Parse(). Decryption Digest described a similar mechanism centered on the ToolPane component and the ability to register .NET classes outside the SafeControls filter, leading to remote code execution.
What patches and fixed versions were reported?
The Canadian Centre for Cyber Security, in its AL26-023 advisory cited by Provintell, listed fixed versions for the affected editions. For SharePoint Enterprise Server 2016, it cited build 16.0.5565.1001. For SharePoint Server 2019, it cited 16.0.10417.20198. For SharePoint Server Subscription Edition, it cited 16.0.19725.20522.
The Cyber Express added that the vulnerability had a base CVSS score of 8.8 and listed related fixes tied to KB 5002893 for Subscription Edition, KB 5002894 and KB 5002896 for SharePoint 2019, and KB 5002905 and KB 5002906 for SharePoint 2016. CISA's decision to include it in the KEV was based on that mix of official alerts and technical analysis.
Sources
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wildthehackernews.com· The Hacker News
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacksbleepingcomputer.com· BleepingComputer
- CVE-2026-65660: CISA Flags Exploited SharePoint Code Injectionwindowsforum.com· Windows Forum
- Microsoft Warns SharePoint Vulnerability CVE-2026-65660 Could Lead to Command Execution on Serversthaicert.or.th· ThaiCERT
- Actively Exploited SharePoint Server Code Injection Flaw Puts On-Premises Deployments at Riskprovintell.com· Canadian Centre for Cyber Security / Provintell
- CVE-2026-65660: SharePoint RCE Flaw Mislabeled As Spoofingthecyberexpress.com· The Cyber Express
- U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com· Security Affairs
- SharePoint CVE-2026-65660: Code Injection Exploiteddecryptiondigest.com· Decryption Digest



