• Tech Support ⤴
  • Projects
  • Services
    • AI Development
    • UI/UX Design
    • Web Development
    • Technology Support
    • Mobile App Development
    • Banking ATM Interfaces
    • Process Automation
    • Security Auditing
    • Local AI Servers
  • odoo ERP
get in touchStart with Eva
logo
Tech Support ⤴
Projects
Services
AI DevelopmentUI/UX DesignWeb DevelopmentTechnology SupportMobile App DevelopmentBanking ATM InterfacesProcess AutomationSecurity AuditingLocal AI Servers
odoo ERP
get in touchStart with Eva
Loading…
logo

Transforming businesses through AI-powered digital innovation and creative excellence.

Quick Links

BlogAinexProjectsContact us

Contact Us

pinDubai Digital Park, A5, DTEC - Silicon Oasisemail[email protected]phone+971 55 7538087
© 2026 aratech. All rights reserved.
Privacy PolicyTerms of ServiceCookie Policy
Home / Blog / SharePoint CVE-2026-65660: Attackers Are Actively Breaching Unpatched Servers

SharePoint CVE-2026-65660: Attackers Are Actively Breaching Unpatched Servers

Microsoft confirmed that attackers are actively exploiting CVE-2026-65660, a SharePoint Server deserialization RCE chained with anonymous-access misconfigurations to drop web shells. CISA added it to KEV on September 25 and federal agencies must patch by September 28. Here is what the exploit chain looks like and a prioritized defense checklist.

September 29, 2026 - 7 min read

Key Takeaways

ExpandCollapse
  • - CVE-2026-65660 is an actively exploited SharePoint Server RCE via ToolPane web part markup passed to a bypassable XamlServices deserialization path
  • - Chained with anonymous-access misconfigurations, observed attacks drop two-stage web shells for pre-authentication footholds
  • - Microsoft confirmed active exploitation on September 25, 2026 and CISA added the CVE to KEV the same day with a September 28 federal patch deadline
  • - Patch the September 2026 SharePoint updates immediately and verify build numbers rather than installer exit codes
  • - Hunt for web shells now: scan _layouts, _cts and custom ASPX directories and watch for w3wp.exe spawning cmd, powershell or certutil
Dark cyberpunk artwork of a breached glowing SharePoint-style server rack with neon purple and cyan light, symbolizing the actively exploited CVE-2026-65660 vulnerability

SharePoint CVE-2026-65660: Attackers Are Actively Breaching Unpatched Servers

Update your SharePoint servers today. Microsoft confirmed that attackers are actively exploiting CVE-2026-65660, a remote code execution flaw in SharePoint Server, and CISA added it to the Known Exploited Vulnerabilities catalog on September 25, 2026. Federal civilian agencies have until the end of September 28 to patch. If your organization runs SharePoint Server on-premises and you have not applied the September updates yet, you are officially in the blast zone.

What exactly is CVE-2026-65660?

At its core, this is a deserialization vulnerability in how SharePoint Server processes ToolPane web part markup. When SharePoint receives specially crafted markup, it passes it to the .NET XamlServices deserializer, and the type-checking logic that is supposed to prevent dangerous types from loading can be bypassed. The result is remote code execution with the privileges of the SharePoint web application's service account, usually w3wp.exe under the SharePoint app pool identity.

Microsoft rates it Critical with a CVSS score of 7.8, but the real-world risk is higher because of how it chains with misconfigurations: web shells have been observed dropping onto sites that allow anonymous access. That combination, flawed deserialization plus overly open anonymous access, turns a bug that would normally require authentication into a pre-authentication foothold.

The exploitation pattern: two-stage web shell deployment

Security researchers at Previdian published detailed analysis of real exploitation attempts, and the pattern is consistent and easy to hunt for:

  1. The attacker submits crafted ToolPane web part markup to the vulnerable endpoint.
  2. SharePoint's weak type restrictions let the markup trigger execution through XamlServices, spawning a process under the web app identity.
  3. A first-stage web shell is written into SharePoint's layout directories, giving the attacker persistent command execution over HTTP.
  4. From there, second-stage tooling (credential theft, lateral movement) follows, classic hands-on-keyboard intrusion behavior.

This is not a sophisticated zero-browser exploit chain. It is a deliberate, loud, network-visible operation, which is good news for defenders who know what to look for.

Why this one is different from routine Patch Tuesday bugs

Three things elevate this from "another CVE" to "drop everything":

  • Microsoft confirmed active exploitation in the wild on September 25, 2026.
  • CISA added it to KEV the same day, with a hard remediation deadline for federal agencies.
  • Patch rigor is binary: either you have the September 2026 security update (or later) or you are exploitable. There is no partial mitigation posture that meaningfully protects you.

Organizations that skipped August and September Patch Tuesdays are the primary targets, and scanning tools are already fingerprinting unpatched SharePoint deployments at scale.

Your defense checklist, in priority order

  1. Patch immediately. Apply the September 2026 cumulative update for SharePoint Server (Subscription Edition and 2019 are both affected lines). Verify the build number changes; do not trust the installer exit code alone.
  2. Restrict anonymous access. Audit every SharePoint web application and site collection. Anonymous access plus this bug is the observed pre-auth kill chain.
  3. Hunt for web shells now. Look for recently modified or created files in SharePoint's _layouts, _cts, and custom ASPX directories. Compare file counts and timestamps against a known-good baseline.
  4. Check your logs. Scan IIS and SharePoint ULS logs for unusual POST requests to ToolPane endpoints and for process spawns from w3wp.exe, anything spawning cmd.exe, powershell.exe, or certutil.exe commands.
  5. Isolate and rebuild if compromised. If you find indicators, treat the server as fully compromised: capture forensics, pull it from the farm, and rebuild from clean media with the latest updates.
  6. Shrink the attack surface. Never expose SharePoint admin endpoints directly to the internet. Put authentication in front of everything, ideally MFA-protected.

The takeaway for your organization

This vulnerability is a case study in why patch velocity and configuration hygiene must move together. The organizations getting bitten are those that delayed updates or left anonymous access wide open. Fixing one without the other leaves you exposed.

At Aratech, we help UAE and regional businesses build exactly this muscle: automated patch pipelines, hardened SharePoint and Microsoft 365 configurations, and continuous monitoring that catches web shells before they become breach headlines. If your SharePoint estate has not been verified against CVE-2026-65660 yet, treat that as today's highest-value cybersecurity task. Get in touch, and we will help you audit, patch, and lock it down.

Table of Contents

  • ↗What exactly is CVE-2026-65660?
  • ↗The exploitation pattern: two-stage web shell deployment
  • ↗Why this one is different from routine Patch Tuesday bugs
  • ↗Your defense checklist, in priority order
  • ↗The takeaway for your organization

Related Posts

Dark cyberpunk illustration of a webmail server database under SQL injection attack, with neon purple and cyan circuit lines

Roundcube's Forgotten Plugin: A Four-Month-Old SQL Injection Is Now Running in the Wild

Roundcube Webmail's virtuser_query plugin carries CVE-2026-48842, a pre-authentication SQL injection that was patched back in May 2026. On September 24, Canada's Cyber Centre confirmed attackers are exploiting it in the wild, and any unpatched webmail server is an open door into the database behind it.

Necolas HamwiNecolas Hamwi
September 25, 2026 - 7 min read
Dark cyberpunk hero image of a glowing identity gateway cracking open, neon purple and cyan light spilling from a fractured hexagonal key matrix.

The Door That Hands Out the Keys: F5 BIG-IP APM Zero-Day CVE-2026-94127 Is Under Active Attack

F5 has confirmed active exploitation of CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP APM running as an OAuth authorization server. The flaw lives on the data plane, so locking down the management interface does nothing, and Appliance mode is vulnerable too. CISA gave federal agencies three days to act.

Necolas HamwiNecolas Hamwi
September 24, 2026 - 7 min read
Dark cyberpunk illustration of a firewall shield cracking open with cyan light and shattered certificate fragments

Your Firewall's Front Door Was Left Open: Check Point's Pre-Auth RCE Is Under Active Attack

Check Point Research has confirmed active exploitation of CVE-2026-85102, a CVSS 9.8 pre-authentication RCE in the VPN certificate handling of Security Gateway and Spark Firewall. The fix shipped on September 9; attack attempts began three days later. A second pre-auth flaw in Security Management, CVE-2026-93616, is also being exploited.

Necolas HamwiNecolas Hamwi
September 23, 2026 - 7 min read