On September 24, 2026, Canada’s Cyber Centre reported active exploitation of CVE-2026-65660 in Microsoft SharePoint Server. The code-injection vulnerability affects on-premises 2016, 2019 and Subscription Edition deployments and can allow an authenticated attacker to execute code.
The scope matters: the alert concerns SharePoint Server farms managed by organisations, not a general incident affecting SharePoint Online. Patching should still be followed by an investigation when a farm was reachable or a privileged account could access it.
What CVE-2026-65660 does
Microsoft describes the issue in its security guide, while technical analyses detail an insufficiently controlled code-generation path. The documented consequence is code execution on the vulnerable server in the context available to the attacker.
The flaw does not mean every SharePoint site was compromised. It does require checking versions, exposure, authorised accounts and changes in the farm.
The active-exploitation signal
The Canadian alert cites active exploitation and links to Microsoft’s update. Independent analyses describe the execution risk but do not provide a complete victim list.
Treat a vulnerable farm as high priority without declaring compromise before finding evidence in IIS, process, file, account or configuration logs.
Administrator checks
Inventory SharePoint Server 2016, 2019 and Subscription Edition, then apply the Microsoft updates for each farm. Restrict administrative access and remove unnecessary permissions while investigating.
Preserve IIS, SharePoint, Windows and authentication logs. Look for unusual requests, unexpected ASPX files, child processes of w3wp.exe, recently created accounts and unusual outbound connections.
After a suspicion
Isolate the affected farm without destroying evidence. Rotate service secrets, administrator credentials and keys that may have been reachable, then review connected systems and sensitive libraries.
Users should treat reset or sharing requests arriving after the alert carefully. A compromised collaboration server can also support targeted phishing even when the exact data accessed is not yet known.
The Soclyde connection
Soclyde does not patch SharePoint or replace an investigation of an on-premises farm. It can help teams prepare a documented access rotation: generating unique secrets and keeping them in local-first encrypted vaults avoids copying them into temporary scripts or tickets.
That organisation reduces secret copies during response; it does not detect exploitation or guarantee SharePoint integrity.
Key takeaways
CVE-2026-65660 is being exploited against on-premises SharePoint Server. Patch farms, distinguish Server from Online, preserve logs and investigate execution evidence before deciding on broad rotation. Read the secure password generator guide or contact Soclyde.



