Vulnerability  ·  2026-09-26

KEV: Microsoft SharePoint code injection actively exploited (CVE-2026-65660)

VulnerabilityMedium impactGlobalCVE-2026-65660
CISA KEV addition 25 Sept 2026 for SharePoint code injection (CVE-2026-65660); Microsoft's update was released in August and the exploit markup is public; it enables network-based code execution by an authorized attacker.
SharePoint is the data estate under Microsoft 365 Copilot and other AI agents; an exploited SharePoint RCE gives attackers write access to the documents and content that enterprise AI assistants index and trust.
Authorized attacker code injection over the network in SharePoint; added to CISA KEV 25 Sept 2026 with confirmed in-the-wild exploitation; Microsoft originally rated it spoofing, later a CVE re-evaluation titled it RCE.
Microsoft SharePoint (code injection; August patch turns off the vulnerable function by default)
Apply the Microsoft August 2026 security update (patch disables the vulnerable function by default); follow MSRC guidance for CVE-2026-65660.
CISA KEV catalogMSRC CVE-2026-65660
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →