CISA added SharePoint code injection flaw CVE-2026-65660 to KEV on 25 Sep. Previdian says it was rescored from 6.5 spoofing to 8.8 RCE and saw attack attempts.
CVE-2026-65660, a code injection flaw in on-premises Microsoft SharePoint Server, was added to CISA's Known Exploited Vulnerabilities catalog on 25 September 2026, with a federal remediation deadline of 28 September. Microsoft released the fix on 11 August. According to security firm Previdian, the CVE record first described the flaw as spoofing with a CVSS 3.1 score of 6.5, and it was changed to remote code execution at 8.8 by 27 August. Teams that triaged it as medium severity in August should reassess now.
This is a separate issue from an earlier SharePoint zero-day, CVE-2026-56164.
Who is affected
NVD, citing Microsoft's record, lists these builds as vulnerable:
| Product | Vulnerable below | KB articles (per MSRC) |
|---|---|---|
| SharePoint Enterprise Server 2016 | 16.0.5565.1001 | 5002905, 5002906 |
| SharePoint Server 2019 | 16.0.10417.20198 | 5002894, 5002896 |
| SharePoint Server Subscription Edition | 16.0.19725.20522 | 5002893 |
The MSRC record rates it Important, marks customer action as required and lists the impact as Remote Code Execution. The flaw is CWE-94 code injection that lets an authorized attacker execute code over a network. The 8.8 vector, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, requires low privileges and no user interaction.
The rescore
According to Previdian's analysis, Microsoft's 11 August CVE record described an authorized attacker performing spoofing, with a base score of 6.5. Previdian says the CVE record was changed to remote code execution and 8.8, and that the change is present in the 27 August record. We could not independently retrieve the original 6.5 record. Previdian says the live advisory records a 27 August revision to the title, impact and FAQs, which Microsoft labels informational, and that the security update itself was released on 11 August. The current MSRC data and the NVD entry both show 8.8, and MSRC lists Remote Code Execution (we checked both on 3 October).
What Previdian observed
Previdian reports that on 24 September 2026, at about 12:00 UTC, its SharePoint honeypot received 12 POST requests from a single source, 169.150.248[.]21 (AS212238, Datacamp Limited). The requests went to six URL paths, built from /_layouts/15/AddGallery.aspx and /_layouts/15/designgallery.aspx plus retries with extra layout prefixes. They carried the query string job=all&DisplayMode=Edit and the form fields MSOTlPn_Uri and MSOTlPn_DWP. The user agent was Firefox 120, and no cookie or Authorization header was present.
Each path received two bodies, the smaller first:
- Stage one (7,834 bytes): an ActivitySurrogateDisableTypeCheck gadget, intended to switch off a .NET deserialization safeguard.
- Stage two (535,404 bytes): an ActivitySurrogate gadget embedding an assembly named wt3k3sij.dll with a loader type called SdLoader. The loader contains AES decryption and an Assembly.Load call. Previdian has not recovered the decrypted final assembly, so what it does is unknown.
Previdian says the payloads match the SafeControls quote-injection technique in published research from Viettel Cyber Security.
Why unauthenticated attempts matter
CVE-2026-65660 itself requires authentication. Previdian says the traffic pairs it with a separate anonymous delivery bug. Before its fix, a WebPartPage containing a zone, such as AddGallery.aspx, could create a ToolPane in edit mode without an authentication check. That route works only on sites configured to allow anonymous viewing. Previdian, citing Viettel, says that bug was fixed on 9 June 2026. No CVE identifier has been published for it that we could find, and the Viettel author says he does not know one. We do not name one here.
Previdian therefore classes the traffic as an attempted pre-authentication chain that depends on both weaknesses and on anonymous viewing being enabled.
Hunting leads (defanged)
Previdian lists these. They come from a single vendor's honeypot data and are leads, not confirmed indicators of compromise:
- Source IP: 169.150.248[.]21
- Requests to /_layouts/15/AddGallery.aspx or /_layouts/15/designgallery.aspx with DisplayMode=Edit and no authentication material
- Form value hxxp://asdf/_controltemplates/15/AclEditor[.]ascx. Previdian says this is not established as command-and-control infrastructure.
- wt3k3sij.dll, 391,680 bytes, SHA-256 d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742
- 24e5mo4s.dll, 4,096 bytes, SHA-256 a151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1
- A webshell at /_layouts/15/sphealth.aspx
A caveat on the last three: a 25 September update to Previdian's post says exploitation creates the webshell and binaries, but the body of the same post says a file named wt3k3sij.dll was not observed being written. Treat them as hunting leads. Do not treat their presence or absence as proof of compromise or safety.
What defenders should do
- Patch. Install the applicable update for each farm server and confirm the build is at or above the fixed version in the table. Previdian, citing Microsoft's FAQ, says all applicable update packages for the installed product must be applied and the configuration steps completed across the farm.
- Treat the CISA deadline as passed. The 28 September due date is already behind us for federal agencies, and any private farm still unpatched is exposed to a flaw that CISA lists as exploited.
- Review anonymous access. Anonymous viewing is the prerequisite for the delivery route Previdian describes. Restrict it where it is not needed.
- Hunt. Search IIS logs from 24 September onward for POSTs to the two gallery pages with DisplayMode=Edit, especially closely spaced requests from one source and layout-prefix variants. Check for sphealth.aspx and the two DLL names and hashes above.
- Re-triage. If this CVE was filed as medium-severity spoofing in August, update the ticket and the SLA.
What is not known
Previdian's data comes from one honeypot and one source address. It does not identify the operator, show the final payload, or show compromise of any real deployment. It also notes that automated testing or research cannot be ruled out from the requests alone. CISA's KEV listing and its SSVC entry dated 24 September (exploitation: active, technical impact: total) confirm exploitation is occurring, but neither source gives victim counts or attribution.