SharePoint CVE-2026-65660: Attackers Are Actively Breaching Unpatched Servers
Update your SharePoint servers today. Microsoft confirmed that attackers are actively exploiting CVE-2026-65660, a remote code execution flaw in SharePoint Server, and CISA added it to the Known Exploited Vulnerabilities catalog on September 25, 2026. Federal civilian agencies have until the end of September 28 to patch. If your organization runs SharePoint Server on-premises and you have not applied the September updates yet, you are officially in the blast zone.
What exactly is CVE-2026-65660?
At its core, this is a deserialization vulnerability in how SharePoint Server processes ToolPane web part markup. When SharePoint receives specially crafted markup, it passes it to the .NET XamlServices deserializer, and the type-checking logic that is supposed to prevent dangerous types from loading can be bypassed. The result is remote code execution with the privileges of the SharePoint web application's service account, usually w3wp.exe under the SharePoint app pool identity.
Microsoft rates it Critical with a CVSS score of 7.8, but the real-world risk is higher because of how it chains with misconfigurations: web shells have been observed dropping onto sites that allow anonymous access. That combination, flawed deserialization plus overly open anonymous access, turns a bug that would normally require authentication into a pre-authentication foothold.
The exploitation pattern: two-stage web shell deployment
Security researchers at Previdian published detailed analysis of real exploitation attempts, and the pattern is consistent and easy to hunt for:
- The attacker submits crafted ToolPane web part markup to the vulnerable endpoint.
- SharePoint's weak type restrictions let the markup trigger execution through
XamlServices, spawning a process under the web app identity. - A first-stage web shell is written into SharePoint's layout directories, giving the attacker persistent command execution over HTTP.
- From there, second-stage tooling (credential theft, lateral movement) follows, classic hands-on-keyboard intrusion behavior.
This is not a sophisticated zero-browser exploit chain. It is a deliberate, loud, network-visible operation, which is good news for defenders who know what to look for.
Why this one is different from routine Patch Tuesday bugs
Three things elevate this from "another CVE" to "drop everything":
- Microsoft confirmed active exploitation in the wild on September 25, 2026.
- CISA added it to KEV the same day, with a hard remediation deadline for federal agencies.
- Patch rigor is binary: either you have the September 2026 security update (or later) or you are exploitable. There is no partial mitigation posture that meaningfully protects you.
Organizations that skipped August and September Patch Tuesdays are the primary targets, and scanning tools are already fingerprinting unpatched SharePoint deployments at scale.
Your defense checklist, in priority order
- Patch immediately. Apply the September 2026 cumulative update for SharePoint Server (Subscription Edition and 2019 are both affected lines). Verify the build number changes; do not trust the installer exit code alone.
- Restrict anonymous access. Audit every SharePoint web application and site collection. Anonymous access plus this bug is the observed pre-auth kill chain.
- Hunt for web shells now. Look for recently modified or created files in SharePoint's
_layouts,_cts, and custom ASPX directories. Compare file counts and timestamps against a known-good baseline. - Check your logs. Scan IIS and SharePoint ULS logs for unusual
POSTrequests to ToolPane endpoints and for process spawns fromw3wp.exe, anything spawningcmd.exe,powershell.exe, orcertutil.execommands. - Isolate and rebuild if compromised. If you find indicators, treat the server as fully compromised: capture forensics, pull it from the farm, and rebuild from clean media with the latest updates.
- Shrink the attack surface. Never expose SharePoint admin endpoints directly to the internet. Put authentication in front of everything, ideally MFA-protected.
The takeaway for your organization
This vulnerability is a case study in why patch velocity and configuration hygiene must move together. The organizations getting bitten are those that delayed updates or left anonymous access wide open. Fixing one without the other leaves you exposed.
At Aratech, we help UAE and regional businesses build exactly this muscle: automated patch pipelines, hardened SharePoint and Microsoft 365 configurations, and continuous monitoring that catches web shells before they become breach headlines. If your SharePoint estate has not been verified against CVE-2026-65660 yet, treat that as today's highest-value cybersecurity task. Get in touch, and we will help you audit, patch, and lock it down.