Vulnerability
Published 2026-08-11
Verified 2026-09-27

Microsoft SharePoint CVE-2026-65660 authenticated RCE (MSRC CVSS 8.8); CISA KEV 25 Sep — Viettel SafeControls/ToolPane chain (Aug patch)

MSRC CVE-2026-65660 (August 2026 CSPU; latest revision 27 Aug 2026) is a SharePoint Server code-injection RCE: an authorized low-privilege attacker can execute code over the network without user interaction. Microsoft scores CVSS 3.1 8.8 Important (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H); exploited: No; exploitation less likely. Viettel Cyber Security (Dinh Ho Anh Khoa; technical details amplified 22 Sep 2026) shows the bug in SafeControls/ToolPane Register-directive reconstruction (unescaped quotes → arbitrary .NET class load → XamlServices.Parse webshell) and notes Microsoft’s HTML advisory initially framed it as spoofing/CVSS 6.5 while the CVE record titles RCE. Affects SharePoint Server 2016, 2019, Subscription Edition (researcher also claims 2013 EOL). August 11 updates fix; can chain with already-patched auth bypass for pre-auth RCE only if that June fix was missed. Distinct from desk CVE-2026-55040 / CVE-2026-63520. UPDATE 25 Sep 2026: CISA added CVE-2026-65660 to KEV (dateAdded 2026-09-25; federal due date 28 Sep 2026) alongside WSO2/Adobe Magento KEV adds — treat internet-facing SharePoint as priority even if MSRC still lists exploitation less likely. Primary: MSRC; KEV: CISA; wire: BleepingComputer / The Hacker News.

Product
Microsoft SharePoint Server 2016 / 2019 / Subscription Edition
Versions
Patched in August 11, 2026 SharePoint security updates (MSRC release 2026-Aug). Confirm all offered KBs applied for each installed SKU; SharePoint 2013 EOL (no fix).
CVSS
(CVSS 3.1 Important; Microsoft)
Exploited in Australia?
unknown
Patch to
Apply August 2026 SharePoint security updates for 2016/2019/Subscription Edition; verify June auth-bypass patches are present so pre-auth chaining is closed; restrict SharePoint admin/contributor roles; hunt ToolPane/web-part abuse and anomalous SafeControls registration

Primary: MSRC — CVE-2026-65660 SharePoint Server RCE (Aug 2026) · Vendor: Microsoft Security Response Center — CVE-2026-65660 · CVE: CVE-2026-65660, CVE-2026-55040, CVE-2026-63520 · The Hacker News — Viettel SharePoint CVE-2026-65660 RCE details (22 Sep 2026)

vulnerabilities identity cloud