Executive Summary
CVE-2026-65660 is a critical vulnerability affecting Microsoft SharePoint Server (2016, 2019, and Subscription Edition), enabling remote code execution (RCE) by authenticated, low-privileged users. Initially classified as a spoofing issue, subsequent technical analysis and public proof-of-concept (PoC) code have demonstrated that this flaw is, in fact, a code injection vulnerability with severe implications for enterprise environments. The vulnerability has now been confirmed as actively exploited in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog. The widespread deployment of Microsoft SharePoint in critical business operations, combined with the availability of public exploit code, significantly elevates the risk profile for organizations that have not yet applied the relevant security updates.
Threat Actor Profile
While no specific advanced persistent threat (APT) group has been publicly attributed to the exploitation of CVE-2026-65660 as of this report, historical patterns indicate that Chinese state-backed actors and other sophisticated threat groups have previously targeted Microsoft SharePoint vulnerabilities for initial access and lateral movement. These actors are known for rapidly weaponizing newly disclosed RCE vulnerabilities, especially when public PoC code is available. The exploitation of SharePoint flaws has been observed in campaigns targeting government, defense, finance, and critical infrastructure sectors. The current exploitation landscape suggests that both opportunistic cybercriminals and state-sponsored actors are likely to leverage this vulnerability for initial access, persistence, and post-exploitation activities such as data exfiltration and deployment of webshells.
Technical Analysis of Malware/TTPs
CVE-2026-65660 is rooted in the improper handling of Register directives within the SharePoint SafeControls mechanism. The vulnerability arises when the ToolPane component processes web-part markup and reconstructs Register directives by writing attribute values between double quotes, failing to escape embedded quotes. This oversight allows attackers to inject additional directives, registering arbitrary .NET classes after the type check but before the control is loaded. By leveraging this flaw, an attacker can invoke the XamlServices.Parse() method, which deserializes attacker-supplied XAML payloads, resulting in arbitrary code execution within the context of the SharePoint application pool.
The exploitation chain typically involves an authenticated, low-privileged user uploading a malicious web-part or exploiting a previously patched authentication bypass (fixed June 9, 2026) to achieve pre-authentication RCE on servers with anonymous access enabled. Public PoC code demonstrates the deployment of in-memory webshells, which are particularly challenging to detect due to their lack of persistence on disk and evasion of traditional file-based security controls. The attack surface is further expanded by the ability to chain this vulnerability with other privilege escalation or lateral movement techniques, enabling attackers to establish robust footholds within targeted environments.
Observed Tactics, Techniques, and Procedures (TTPs) include the use of malformed Register directives, exploitation of deserialization via XamlServices.Parse(), and the deployment of in-memory webshells for command execution and persistence. These TTPs align with the following MITRE ATT&CK techniques: T1190 (Exploit Public-Facing Application), T1059 (Command and Scripting Interpreter), and T1505.003 (Web Shell).
Exploitation in the Wild
Active exploitation of CVE-2026-65660 has been confirmed by multiple security researchers and government agencies, including CISA, which has added the vulnerability to its KEV catalog. Exploitation attempts have been observed in both penetration testing engagements and real-world attacks targeting unpatched SharePoint servers. The availability of public PoC code has accelerated the adoption of this exploit by both sophisticated and opportunistic threat actors.
Attackers are leveraging the vulnerability to deploy in-memory webshells, establish command-and-control (C2) channels, and facilitate lateral movement within compromised networks. The exploitation is not limited to targeted attacks; automated scanning and exploitation tools are being used to identify and compromise vulnerable SharePoint instances exposed to the internet. While no specific APT attribution has been made public, the rapid weaponization of this vulnerability mirrors previous campaigns involving SharePoint RCE flaws, such as those exploited by Chinese state-backed groups following public disclosures at events like Pwn2Own Berlin 2025.
Victimology and Targeting
The primary targets of CVE-2026-65660 exploitation are organizations running unpatched versions of Microsoft SharePoint Server 2016, 2019, and Subscription Edition. Sectors at heightened risk include government, defense, finance, healthcare, and critical infrastructure, where SharePoint is commonly used for document management, collaboration, and workflow automation. The vulnerability is particularly impactful in environments where SharePoint servers are exposed to the internet or where anonymous access is enabled, increasing the likelihood of exploitation by both targeted and opportunistic actors.
Geographically, while no specific countries have been singled out in public reporting, the global prevalence of Microsoft SharePoint means that organizations across all regions are at risk. Historical exploitation patterns suggest that entities in North America, Europe, and Asia-Pacific are likely to be targeted, especially those with high-value intellectual property or sensitive data.
Mitigation and Countermeasures
Immediate action is required to mitigate the risk posed by CVE-2026-65660. Organizations should apply the Microsoft security update released on August 11, 2026, for SharePoint Server 2016, 2019, and Subscription Edition without delay. For environments running SharePoint Server 2013, which is no longer supported, organizations must prioritize upgrading to a supported version or isolating these systems from the network to prevent exploitation.
In addition to patching, organizations should disable anonymous access to SharePoint sites unless absolutely necessary, as this significantly reduces the attack surface. Security teams should monitor for indicators of compromise (IOCs), including unusual or malformed Register directives in web-part markup, unexpected logins from low-privileged accounts, anomalous process creation events, and outbound network connections from SharePoint servers to external infrastructure.
Advanced detection strategies should include memory analysis for in-memory webshells, behavioral monitoring for deserialization activity via XamlServices.Parse(), and correlation of authentication and process logs to identify lateral movement attempts. Organizations are also advised to review and harden their SharePoint configurations, restrict access to administrative interfaces, and implement network segmentation to limit the potential impact of a successful compromise.
References
The following sources provide additional technical details and context regarding CVE-2026-65660 and its exploitation:
The Hacker News – SharePoint Flaw Enables Authenticated RCE: https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
Security Affairs – CISA Adds SharePoint Flaw to KEV: https://securityaffairs.com/199777/hacking/u-s-cisa-adds-microsoft-sharepoint-and-mikrotik-routeros-flaws-to-its-known-exploited-vulnerabilities-catalog.html
Viettel Cyber Security – Technical Writeup: https://blog.viettelcybersecurity.com/sharepoint_cve-2026-65660/
CVE Record: https://www.cve.org/CVERecord?id=CVE-2026-65660
Reddit BlueTeamSec Discussion: https://www.reddit.com/r/blueteamsec/comments/1wpmujc/sharepoint_cve202665660_from_anonymous_access_to/
CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their supply chain and digital ecosystem. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify vulnerabilities, prioritize remediation efforts, and enhance overall cyber resilience. For more information about our solutions or to discuss your organization’s cybersecurity needs, we are happy to answer questions at info@rescana.com.



