Close Menu
NCIJ Network NCIJ Network
    What's Hot

    My Instagram reels addiction has ruined my ability to have a conversation. But can I get it back? | Hannah Ewens

    September 27, 2026

    Time running out for Tennessee killer Christa Pike who says she’s too damaged for death row

    September 27, 2026

    A Coding Guide to Google Research’s MSEB: Writing Sound Encoders to the Benchmark Contract and Scoring Them Across Classification, Clustering, Retrieval and Segmentation

    September 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • My Instagram reels addiction has ruined my ability to have a conversation. But can I get it back? | Hannah Ewens
    • Time running out for Tennessee killer Christa Pike who says she’s too damaged for death row
    • A Coding Guide to Google Research’s MSEB: Writing Sound Encoders to the Benchmark Contract and Scoring Them Across Classification, Clustering, Retrieval and Segmentation
    • Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
    • Why your tokenized stock could stop trading for three months
    • The Trump Administration’s Critical Minerals Agenda Comes for America’s ‘Forgotten Wildlife Corridor’
    • ‘Russian sleeper cell’: Can Germany’s far-right AfD be barred from sensitive intel?
    • UK politics live: Burnham says NHS will ‘break’ without social care reform ahead of Labour conference | Politics
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 27, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is now being exploited in attacks, roughly six weeks after Microsoft announced patches and a couple of days after researchers disclosed technical details.

    CVE-2026-65660 is a remote code execution vulnerability fixed by Microsoft with its August 2026 Patch Tuesday updates. The company’s advisory describes it as a code injection issue that lets an authenticated attacker with low-level access to an affected server execute arbitrary code without user interaction. 

    “As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability,” Microsoft said in its updated advisory. 

    CISA added CVE-2026-65660 to its KEV catalog on September 25, giving federal agencies a patching deadline of September 28.

    Early-warning threat intelligence platform Previdian (formerly KEVIntel) reported seeing exploitation attempts on September 24. On September 25, the company saw attempts to create a webshell backdoor. 

    It’s unclear who is behind the attacks, which appear to have started shortly after Viettel Security, whose researchers reported the vulnerability to Microsoft, disclosed technical details.

    Advertisement. Scroll to continue reading.

    Viettel noted that Microsoft initially classified the vulnerability as a medium-severity spoofing issue, but later revised its assessment to a high-severity remote code execution flaw.

    Microsoft rates CVE-2026-65660 as an authenticated flaw, requiring low-level privileges but no user interaction. On its own, the vulnerability is a type-check bypass that yields code execution for an authenticated attacker; reaching unauthenticated RCE requires chaining it with a separate authentication bypass weakness.

    Previdian noted that the in-the-wild exploits it observed appeared to be based on the technical information shared by Viettel.

    CISA’s KEV catalog currently includes 16 SharePoint vulnerabilities, including eight discovered and patched this year.

    Related: Critical WordPress Vulnerability Exploited Immediately After Disclosure

    Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day

    Related: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

    attacks CVE202665660 Exploited Flaw Microsoft SharePoint
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

    GitHub Actions re-enabled with Mini Shai-Hulud payload still active

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    Windows, Linux, Android File Notification Systems Leak User Activity

    China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    My Instagram reels addiction has ruined my ability to have a conversation. But can I get it back? | Hannah Ewens

    September 27, 2026

    Time running out for Tennessee killer Christa Pike who says she’s too damaged for death row

    September 27, 2026

    A Coding Guide to Google Research’s MSEB: Writing Sound Encoders to the Benchmark Contract and Scoring Them Across Classification, Clustering, Retrieval and Segmentation

    September 27, 2026

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    September 27, 2026
    Latest Posts

    5 Best AI Notetakers (2026), Tested and Reviewed

    August 6, 2026

    All schools to get pupil attendance targets, government says

    August 6, 2026

    Trump vows to find ‘leakers’ after reports of depleted Iran war munitions | US-Israel war on Iran News

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    My Instagram reels addiction has ruined my ability to have a conversation. But can I get it back? | Hannah Ewens

    September 27, 2026

    Time running out for Tennessee killer Christa Pike who says she’s too damaged for death row

    September 27, 2026

    A Coding Guide to Google Research’s MSEB: Writing Sound Encoders to the Benchmark Contract and Scoring Them Across Classification, Clustering, Retrieval and Segmentation

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.