CVE-2026-65660 actively exploited: Microsoft SharePoint Code Injection Vulnerability

CISA added CVE-2026-65660, a code injection in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalogue. It could allow an authorized attacker to execute code over a network. Federal agencies must remediate by September 28, 2026.

Microsoft identified a code injection flaw in its SharePoint product. This weakness lets an authorized attacker run malicious code over a network connection. CISA added this specific identifier to its catalogue of known exploited vulnerabilities. The agency noted it is uncertain whether ransomware groups are currently using this exploit. The flaw impacts anyone running the specific version of Microsoft SharePoint noted in the advisory. Federal agencies face a strict deadline to fix the issue. Commercial organizations are not bound by federal orders but remain exposed to the same network risks. Entities with internet-facing instances of this software carry the highest level of risk. Administrators must apply mitigations following vendor instructions. They must also comply with C guidance documents like BOD 26-04. Cloud service users should follow specific guidance or stop using the product if patches are unavailable. Teams need to check their assets for internet exposure. The federal deadline for remediation is September 28, 2026.