Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > SharePoint Code-Injection Bug Joins CISA’s Must-Patch List After Real-World Attacks
SharePoint Code-Injection Bug Joins CISA’s Must-Patch List After Real-World Attacks
Read Time:3 Minute, 30 Second

Microsoft SharePoint is back on the Cybersecurity and Infrastructure Security Agency’s radar. CISA has added a new flaw, tracked as CVE-2026-65660, to its Known Exploited Vulnerabilities (KEV) catalog after confirming the bug is already being exploited in the wild. For any organization still running on-premises SharePoint, the addition is a signal to stop treating this as routine patch-cycle homework and start treating it as an active incident risk.

A Code Injection Flaw With Remote Reach

CISA classifies the vulnerability under CWE-94, improper control of generation of code — more plainly, a code injection issue. These bugs occur when an application takes input it should treat as data and instead lets it run as executable instructions. In SharePoint’s case, successful exploitation lets an authenticated attacker execute arbitrary code remotely, turning a document-sharing platform into a foothold for much deeper compromise.

SharePoint servers are attractive targets precisely because of what they hold: internal documentation, business records, project files, cached credentials, and tight integrations with identity systems. A single working exploit chain can hand an intruder a launchpad into the rest of the network.

“Authenticated Access Required” Isn’t the Reassurance It Sounds Like

The vulnerability does require an attacker to already hold valid credentials or an active session — but security teams shouldn’t read that as a meaningful barrier. Credentials get stolen constantly, through phishing kits, password reuse across services, token theft, compromised third-party accounts, and poorly secured service accounts. Once an attacker clears that low bar, a code-injection flaw converts routine access into full operational control of the server.

A Compressed Timeline From CISA

CISA added CVE-2026-65660 to the KEV catalog on September 25, 2026, and set a remediation deadline of just three days later, September 28 — an unusually tight window that underscores how seriously the agency views ongoing exploitation. There’s no confirmed link to ransomware activity yet, but CISA isn’t treating this as a simple patch-and-move-on situation. Under Binding Operational Directive 26-04, agencies are required to perform forensic triage in addition to remediation, meaning they must actively hunt for signs that they were already compromised before the fix went in.

That directive is legally binding only for federal civilian executive branch agencies, but CISA’s guidance applies just as well to private-sector organizations running the same software, and security teams elsewhere would be wise to mirror the response rather than assume the mandate doesn’t apply to them.

What to Do Right Now

Organizations running on-premises SharePoint should move through a short list of priorities without delay:

  • Inventory every on-premises and managed SharePoint deployment and confirm exact version numbers.
  • Apply Microsoft’s available patches or documented mitigations immediately, following BOD 26-04’s risk-based prioritization.
  • Where no patch is yet available, consider taking the affected service offline rather than leaving it exposed.
  • Reduce unnecessary internet exposure of SharePoint infrastructure.
  • Enforce multi-factor authentication for all administrative and user accounts touching SharePoint.
  • Apply least-privilege permissions and tighten monitoring of privileged account activity.
  • Evaluate network segmentation options to limit how far an attacker can move if a SharePoint server is compromised.

Don’t Skip the Forensic Step

Patching closes the door, but it doesn’t tell you whether someone already walked through it. CISA’s forensic triage requirement is worth taking seriously even outside the federal sector. That means combing through SharePoint and Windows event logs for unusual authenticated activity, checking for recently created or modified SharePoint components, and hunting for web shells, unexpected child processes, or unfamiliar outbound connections originating from SharePoint servers.

Identity logs deserve equal attention: look for atypical sign-ins, unexpected token usage, unauthorized privilege escalations, and authentication attempts from unfamiliar locations or devices. Any of these could indicate that a compromise happened before remediation was in place.

The Bottom Line

Microsoft describes CVE-2026-65660 as a code injection issue that can let an authorized attacker execute code over the network — a description that undersells how damaging it can be once combined with stolen credentials. With CISA confirming active exploitation and setting an aggressive remediation clock, defenders running SharePoint should assume unpatched instances are already being probed, patch without delay, and validate — rather than assume — that no prior compromise occurred.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on SharePoint Code-Injection Bug Joins CISA’s Must-Patch List After Real-World Attacks, use the discussion on Forum.

>> forum community

Comments

Leave a Reply