News

CISA Adds Exploited SharePoint Code Injection to KEV With Only a Three-Day Patch Deadline

A SharePoint bug patched in August is now under attack. CISA gave federal agencies until September 28 to patch and check whether they were already breached.

CISA Adds Exploited SharePoint Code Injection to KEV With Only a Three-Day Patch Deadline

A SharePoint flaw that Microsoft first downplayed is now being used in real attacks. On September 25, Microsoft revised its advisory for CVE-2026-65660 to say it had reliable evidence of exploitation, and CISA added the bug to its Known Exploited Vulnerabilities catalog the same day.

Federal agencies got until September 28 to act. That is a three-day window, and patching alone does not satisfy it.

From spoofing to code execution

The bug is a code injection flaw (CWE-94) in on-premises SharePoint Server. Microsoft fixed it on August 11, Patch Tuesday, but initially described it as a medium-severity spoofing issue. It was later upgraded to an Important remote code execution bug with a CVSS score of 8.8.

Exploitation needs an authenticated user with low privileges and no user interaction. The fixed builds are 16.0.5565.1001 for SharePoint 2016, 16.0.10417.20198 for SharePoint 2019 and 16.0.19725.20522 for Subscription Edition. SharePoint 2016 and 2019 reached end of life on July 15, 2026.

Under BOD 26-04, agencies also have to run forensic triage and check whether they were already compromised. For a bug that has been public for six weeks, that second step may matter more than the patch.

What the attacks look like

Researchers at Previdian logged 12 exploitation requests against a honeypot on September 24, all from 169.150.248.21 (AS212238), Severity Daily reports. The payloads used two-stage deserialization gadgets aimed at dropping a webshell at /_layouts/15/sphealth.aspx and an assembly named wt3k3sij.dll.

The traffic arrived without cookies or an Authorization header. That suggests attackers are trying to skip the login requirement by chaining a separate anonymous WebPartPage issue from June, which never received a CVE. Previdian has not shown the chain succeeding on a real farm, and no named group has been tied to the activity.

Canada's Cyber Centre warns in alert AL26-023 that chaining with other SharePoint flaws can yield unauthenticated code execution on servers that allow anonymous access. It recommends AMSI Full Mode, cutting internet exposure and hunting for webshells and stolen IIS machine keys.

A field that still said no

One detail tripped up automated tooling. On the day Microsoft's prose admitted attacks, the advisory's structured exploited field still read No, with an exploitability rating of Unproven. Scanners that parse that field instead of the text would have missed the change.

CVE-2026-65660 is a different bug from CVE-2026-55040, the SharePoint weak authentication flaw that joined the catalog in August alongside vCenter and macOS entries. SharePoint admins who patched for that one still need the August 11 update for this one.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free