SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityMicrosoft SharePointRCE

Sharepoint: cve-2026-65660 is being exploited on on-premises servers

Canada’s Cyber Centre reports active exploitation of CVE-2026-65660 in on-premises SharePoint Server. Scope, checks and remediation steps.

By Soclyde Team

An administrator checks a collaboration server in an equipment room

In summary

  • CVE-2026-65660 lets an authenticated attacker execute code on vulnerable SharePoint Server versions.
  • The September 24 Canadian alert reports active exploitation; SharePoint Online is not the stated scope.
  • Patch on-premises farms, look for evidence and rotate secrets after a credible suspicion.

Explore next

Soclyde resources

Article contents

On September 24, 2026, Canada’s Cyber Centre reported active exploitation of CVE-2026-65660 in Microsoft SharePoint Server. The code-injection vulnerability affects on-premises 2016, 2019 and Subscription Edition deployments and can allow an authenticated attacker to execute code.

The scope matters: the alert concerns SharePoint Server farms managed by organisations, not a general incident affecting SharePoint Online. Patching should still be followed by an investigation when a farm was reachable or a privileged account could access it.

What CVE-2026-65660 does

Microsoft describes the issue in its security guide, while technical analyses detail an insufficiently controlled code-generation path. The documented consequence is code execution on the vulnerable server in the context available to the attacker.

The flaw does not mean every SharePoint site was compromised. It does require checking versions, exposure, authorised accounts and changes in the farm.

The active-exploitation signal

The Canadian alert cites active exploitation and links to Microsoft’s update. Independent analyses describe the execution risk but do not provide a complete victim list.

Treat a vulnerable farm as high priority without declaring compromise before finding evidence in IIS, process, file, account or configuration logs.

Administrator checks

Inventory SharePoint Server 2016, 2019 and Subscription Edition, then apply the Microsoft updates for each farm. Restrict administrative access and remove unnecessary permissions while investigating.

Preserve IIS, SharePoint, Windows and authentication logs. Look for unusual requests, unexpected ASPX files, child processes of w3wp.exe, recently created accounts and unusual outbound connections.

After a suspicion

Isolate the affected farm without destroying evidence. Rotate service secrets, administrator credentials and keys that may have been reachable, then review connected systems and sensitive libraries.

Users should treat reset or sharing requests arriving after the alert carefully. A compromised collaboration server can also support targeted phishing even when the exact data accessed is not yet known.

The Soclyde connection

Soclyde does not patch SharePoint or replace an investigation of an on-premises farm. It can help teams prepare a documented access rotation: generating unique secrets and keeping them in local-first encrypted vaults avoids copying them into temporary scripts or tickets.

That organisation reduces secret copies during response; it does not detect exploitation or guarantee SharePoint integrity.

Key takeaways

CVE-2026-65660 is being exploited against on-premises SharePoint Server. Patch farms, distinguish Server from Online, preserve logs and investigate execution evidence before deciding on broad rotation. Read the secure password generator guide or contact Soclyde.

Frequently asked questions

Is SharePoint Online affected?

The alert targets on-premises Microsoft SharePoint Server 2016, 2019 and Subscription Edition. It does not describe SharePoint Online in Microsoft 365 as the affected product.

Is patching enough?

No. After patching, preserve logs, look for unusual files or accounts and assess rotating keys and passwords if the farm may have been exploited.

What access does an attacker need?

The sources describe an authenticated attacker with enough privilege to reach the vulnerable path. That requirement does not make an exposed farm safe by default.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading