Urgent: Exploited Code Injection Flaw in Microsoft SharePoint Triggers Alert

CISA has elevated a Microsoft SharePoint vulnerability—CVE-2026-65660—into its catalog of known exploited vulnerabilities after evidence surfaced that the flaw is already in active use. The issue poses a serious threat, allowing attackers with certain permissions to execute arbitrary code remotely, potentially undermining confidentiality, integrity, and availability for organizations using SharePoint for collaboration and document management.

What the Flaw Means

The vulnerability, classified under CWE-94 as code injection or improper control over code generation, arises when externally controlled input is treated as executable code without adequate validation. In SharePoint, this means an attacker who already has valid credentials or an authenticated session can leverage the flaw to run malicious actions—altering data, deploying malware, or gaining deeper network access.

An important nuance: attackers must be authorized in some form—credentials, session, or suitable permissions. But that threshold is not high for sophisticated adversaries. Techniques like phishing, account compromise, or service account misuse can give attackers a foothold from which this vulnerability becomes devastating. Organizations relying on SharePoint often store sensitive data or have integrations with identity systems, increasing the impact.

Urgency and Required Actions

The vulnerability was added to the Known Exploited Vulnerabilities (KEV) Catalog on September 25, 2026, with a remediation deadline of September 28. This tight timeline underscores the severity—vulnerabilities with proof of exploitation demand swift action.

Federal civilian agencies are bound by Binding Operational Directive (BOD) 26-04 to apply patches and conduct forensic investigations. However, private-sector firms should treat this as equally serious. Mere patching may not suffice; organizations must assess forensic data, review identity logs, and scrutinize network and SharePoint server activity for signs of compromise.

Recommended mitigations include applying vendor updates, enforcing least-privilege permissions, restricting unnecessary internet exposure, mandating multifactor authentication, and monitoring for anomalies. For SharePoint instances where mitigations are unavailable, cessation of use may be necessary.

Forensic best practices involve examining Windows and SharePoint event logs, locating suspicious web shells or modified components, tracing unauthorized token use or privilege escalations, and inspecting outbound connections from SharePoint servers. Having visibility into all deployed SharePoint instances—whether on-premises or cloud—is essential.

Why This Matters and What to Look For

This vulnerability strikes at the heart of enterprise ecosystem security. SharePoint is often a central hub for collaboration, file sharing, workflows, and identity integrations — making it a juicy target once attackers gain initial access. What elevates this risk: code injection can morph limited access into widespread compromise. Even organizations that think they’re secure after patching must assume prior exposure.

Defense operations will need to tighten visibility and response, not just patch. Look for suspicious authenticated activity, unknown administrative changes, or presence of tools like web shells. Internal or external exposure of SharePoint servers should be reduced where possible. In short—don’t wait until an incident to catch up.