high Cve 2026 65660 · Exploits

Microsoft SharePoint CVE-2026-65660 Added to CISA KEV After Rescore to RCE

Data graphic: a SharePoint vulnerability, CVE-2026-65660, shown as a struck-out 6.5 'medium spoofing' August score beside a large red 8.8 CVSS 3.1 code-injection rating; the update was released 11 Aug and the flaw was added to CISA's Known Exploited Vulnerabilities list on 25 Sep.
TM

Exploit intelligence researcher · Updated Oct 2, 2026, 3:25 PM EDT

CISA added SharePoint code injection flaw CVE-2026-65660 to KEV on 25 Sep. Previdian says it was rescored from 6.5 spoofing to 8.8 RCE and saw attack attempts.

CVE-2026-65660, a code injection flaw in on-premises Microsoft SharePoint Server, was added to CISA's Known Exploited Vulnerabilities catalog on 25 September 2026, with a federal remediation deadline of 28 September. Microsoft released the fix on 11 August. According to security firm Previdian, the CVE record first described the flaw as spoofing with a CVSS 3.1 score of 6.5, and it was changed to remote code execution at 8.8 by 27 August. Teams that triaged it as medium severity in August should reassess now.

This is a separate issue from an earlier SharePoint zero-day, CVE-2026-56164.

Who is affected

NVD, citing Microsoft's record, lists these builds as vulnerable:

ProductVulnerable belowKB articles (per MSRC)
SharePoint Enterprise Server 201616.0.5565.10015002905, 5002906
SharePoint Server 201916.0.10417.201985002894, 5002896
SharePoint Server Subscription Edition16.0.19725.205225002893

The MSRC record rates it Important, marks customer action as required and lists the impact as Remote Code Execution. The flaw is CWE-94 code injection that lets an authorized attacker execute code over a network. The 8.8 vector, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, requires low privileges and no user interaction.

The rescore

According to Previdian's analysis, Microsoft's 11 August CVE record described an authorized attacker performing spoofing, with a base score of 6.5. Previdian says the CVE record was changed to remote code execution and 8.8, and that the change is present in the 27 August record. We could not independently retrieve the original 6.5 record. Previdian says the live advisory records a 27 August revision to the title, impact and FAQs, which Microsoft labels informational, and that the security update itself was released on 11 August. The current MSRC data and the NVD entry both show 8.8, and MSRC lists Remote Code Execution (we checked both on 3 October).

What Previdian observed

Previdian reports that on 24 September 2026, at about 12:00 UTC, its SharePoint honeypot received 12 POST requests from a single source, 169.150.248[.]21 (AS212238, Datacamp Limited). The requests went to six URL paths, built from /_layouts/15/AddGallery.aspx and /_layouts/15/designgallery.aspx plus retries with extra layout prefixes. They carried the query string job=all&DisplayMode=Edit and the form fields MSOTlPn_Uri and MSOTlPn_DWP. The user agent was Firefox 120, and no cookie or Authorization header was present.

Each path received two bodies, the smaller first:

  • Stage one (7,834 bytes): an ActivitySurrogateDisableTypeCheck gadget, intended to switch off a .NET deserialization safeguard.
  • Stage two (535,404 bytes): an ActivitySurrogate gadget embedding an assembly named wt3k3sij.dll with a loader type called SdLoader. The loader contains AES decryption and an Assembly.Load call. Previdian has not recovered the decrypted final assembly, so what it does is unknown.

Previdian says the payloads match the SafeControls quote-injection technique in published research from Viettel Cyber Security.

Why unauthenticated attempts matter

CVE-2026-65660 itself requires authentication. Previdian says the traffic pairs it with a separate anonymous delivery bug. Before its fix, a WebPartPage containing a zone, such as AddGallery.aspx, could create a ToolPane in edit mode without an authentication check. That route works only on sites configured to allow anonymous viewing. Previdian, citing Viettel, says that bug was fixed on 9 June 2026. No CVE identifier has been published for it that we could find, and the Viettel author says he does not know one. We do not name one here.

Previdian therefore classes the traffic as an attempted pre-authentication chain that depends on both weaknesses and on anonymous viewing being enabled.

Hunting leads (defanged)

Previdian lists these. They come from a single vendor's honeypot data and are leads, not confirmed indicators of compromise:

  • Source IP: 169.150.248[.]21
  • Requests to /_layouts/15/AddGallery.aspx or /_layouts/15/designgallery.aspx with DisplayMode=Edit and no authentication material
  • Form value hxxp://asdf/_controltemplates/15/AclEditor[.]ascx. Previdian says this is not established as command-and-control infrastructure.
  • wt3k3sij.dll, 391,680 bytes, SHA-256 d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742
  • 24e5mo4s.dll, 4,096 bytes, SHA-256 a151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1
  • A webshell at /_layouts/15/sphealth.aspx

A caveat on the last three: a 25 September update to Previdian's post says exploitation creates the webshell and binaries, but the body of the same post says a file named wt3k3sij.dll was not observed being written. Treat them as hunting leads. Do not treat their presence or absence as proof of compromise or safety.

What defenders should do

  1. Patch. Install the applicable update for each farm server and confirm the build is at or above the fixed version in the table. Previdian, citing Microsoft's FAQ, says all applicable update packages for the installed product must be applied and the configuration steps completed across the farm.
  2. Treat the CISA deadline as passed. The 28 September due date is already behind us for federal agencies, and any private farm still unpatched is exposed to a flaw that CISA lists as exploited.
  3. Review anonymous access. Anonymous viewing is the prerequisite for the delivery route Previdian describes. Restrict it where it is not needed.
  4. Hunt. Search IIS logs from 24 September onward for POSTs to the two gallery pages with DisplayMode=Edit, especially closely spaced requests from one source and layout-prefix variants. Check for sphealth.aspx and the two DLL names and hashes above.
  5. Re-triage. If this CVE was filed as medium-severity spoofing in August, update the ticket and the SLA.

What is not known

Previdian's data comes from one honeypot and one source address. It does not identify the operator, show the final payload, or show compromise of any real deployment. It also notes that automated testing or research cannot be ruled out from the requests alone. CISA's KEV listing and its SSVC entry dated 24 September (exploitation: active, technical impact: total) confirm exploitation is occurring, but neither source gives victim counts or attribution.

Sources

Keep reading

All latest →
  1. criticalExploitsShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass5 min
  2. highExploitsZyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV4 min
  3. criticalExploitsWSO2 API Manager JWT Bypass Exploited 133 Days After the Fix5 min
  4. criticalExploitsF5 BIG-IP APM: An Oversized Bearer Token Is Enough for Unauthenticated RCE6 min
  5. highExploitsApple Patches CoreGraphics Zero-Day Used Against Targeted iPhone Users5 min
  6. highExploitsWordPress Core Flaw CVE-2026-87902 Drew Exploit Attempts on Patch Day7 min