A Microsoft SharePoint Server vulnerability patched in August is now being used in attacks, according to Microsoft and threat-intelligence reporting collected by SecurityWeek.
CVE-2026-65660 is a code-injection flaw that can lead to remote code execution on an affected SharePoint server. Microsoft describes the vulnerability as requiring an authenticated attacker with low-level privileges, but no user interaction. An attacker seeking code execution without an account would need to combine it with a separate authentication-bypass weakness.
Microsoft updated its advisory to say it had reliable evidence of observed attacks as of September 25. The Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the same day and gave federal civilian agencies a September 28 deadline to apply the available fixes.
Exploitation followed technical disclosure
Early-warning company Previdian reported exploitation attempts on September 24 and attempts to create a webshell backdoor the following day. SecurityWeek says the activity began shortly after Viettel Security, whose researchers reported the flaw to Microsoft, published technical details.
Microsoft initially classified CVE-2026-65660 as a medium-severity spoofing issue before revising it to a high-severity remote-code-execution vulnerability. Viettel describes the core bug as a type-check bypass.
The identity of the attackers remains unknown. SecurityWeek also notes that the in-the-wild attempts observed by Previdian appeared to use information from Viettel's disclosure, but that connection does not identify who operated them.
Organizations running affected on-premises SharePoint servers should treat the exploitation evidence as a reason to verify their patch state and investigate signs of compromise. CISA's deadline applies directly to covered federal agencies, while the underlying risk extends to any exposed vulnerable deployment.