What happened
CISA KEV addition 25 Sept 2026 for SharePoint code injection (CVE-2026-65660); Microsoft's update was released in August and the exploit markup is public; it enables network-based code execution by an authorized attacker.
Why it matters
SharePoint is the data estate under Microsoft 365 Copilot and other AI agents; an exploited SharePoint RCE gives attackers write access to the documents and content that enterprise AI assistants index and trust.
Attack vector
Authorized attacker code injection over the network in SharePoint; added to CISA KEV 25 Sept 2026 with confirmed in-the-wild exploitation; Microsoft originally rated it spoofing, later a CVE re-evaluation titled it RCE.
Affected systems
Microsoft SharePoint (code injection; August patch turns off the vulnerable function by default)
Mitigation
Apply the Microsoft August 2026 security update (patch disables the vulnerable function by default); follow MSRC guidance for CVE-2026-65660.