CVE-2026-65660 is a code-injection flaw in on-premises Microsoft SharePoint Server (2016, 2019 and Subscription Edition) that lets an attacker run code on the server. Microsoft fixed it in its August 11, 2026 security updates, but first rated it as a medium-severity spoofing bug with a score of 6.5. On August 27 it was reclassified as remote code execution with a score of 8.8.
That reclassification came too late for many teams. On September 24, threat intelligence firm Previdian saw the first exploitation attempts. By September 25 the attacks had moved to dropping web shells, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, and Microsoft confirmed it had reliable evidence of attacks in the wild. Federal agencies were given until September 28 to remediate.
Why should a private company care? Because SharePoint is rarely just a file share. It holds contracts, HR records, engineering documents and the permissions that link them to Active Directory and Microsoft 365. A web shell on that server gives an intruder a quiet, persistent foothold inside the network. For organizations that rely on a managed cybersecurity service with 24/7 SOC, SIEM and MDR, this is the kind of event that should be detected, validated and contained within hours, not discovered months later.
If a fix has existed since August, why is this an emergency? Three reasons make CVE-2026-65660 a textbook case of the modern patching problem.
First, the severity label was wrong at release. Many vulnerability programs sort by score and by category. A flaw labeled as spoofing with a 6.5 rating lands in the next monthly cycle, not in the emergency queue. By the time it became an 8.8 RCE, the clock was already running.
Second, the exploit is a two-stage chain. The flaw itself needs a low-privileged account. Previdian documented attackers pairing it with an anonymous-access bypass, which turns it into pre-authentication code execution on sites that allow anonymous access. Two medium-looking weaknesses combine into one critical path.
Third, SharePoint is a repeat target. CISA's catalog now lists 16 SharePoint vulnerabilities, 8 of them added this year. Teams that treat each advisory as a one-off will keep falling behind.
The practical risk is not only the unpatched server. It is the server that was patched last week but was already compromised on September 24. A web shell survives the update, because the update removes the vulnerability, not the intruder.
What should your team do today? Follow these steps in order.
Confirm your exposure. List every SharePoint Server farm, including forgotten test and departmental instances, and note which are reachable from the internet or allow anonymous access.
Apply the August 2026 updates. The fixed builds are 16.0.19725.20522 or later for Subscription Edition, 16.0.10417.20198 or later for SharePoint 2019, and 16.0.5565.1001 or later for SharePoint 2016. Verify the build number on every server, not just the farm console.
Hunt before you relax. Treat any server that was internet-reachable and unpatched after September 24 as potentially compromised. Search for unexpected .aspx files in SharePoint layout directories, unusual child processes spawned by the IIS worker process, and new scheduled tasks or accounts.
Rotate secrets if you find anything. If there is evidence of a web shell, rotate service account passwords and the farm's machine keys, because the attacker may have read them.
Harden the front door. Place SharePoint behind a reverse proxy that requires authentication, turn on Antimalware Scan Interface (AMSI) integration, and require multi-factor authentication for administrators.
Feed your monitoring. Send SharePoint, IIS and authentication logs to your SIEM and alert on the indicators above, so the next advisory is a search query rather than a scramble.
Teams without the capacity to run this around the clock can lean on managed IT services for asset inventory, patch orchestration and backup, so a recovery point exists if a server must be rebuilt.
Why change how you handle systems that feel like routine internal tools? Because attackers already treat them as high-value entry points.
Faster, cleaner containment. When SharePoint logs are monitored continuously, a web shell appears as an anomaly within hours. Without monitoring, the same intruder can stay for weeks while pivoting to file servers and identity systems.
Less data exposure. SharePoint concentrates sensitive documents. Reducing time-to-detect directly reduces how much data an attacker can copy before you cut access.
Compliance evidence. Regulators, cyber insurers and enterprise customers increasingly ask how quickly exploited vulnerabilities are remediated. A documented process that references the CISA KEV catalog and records the date of each fix answers that with facts.
Smaller blast radius. Segmenting the SharePoint farm from domain controllers and backup systems, using the kind of redundant, segmented paths built with multi-operator connectivity and SD-WAN, limits what a compromised server can reach.
A repeatable playbook. The same steps apply to the next zero-day in a VPN, firewall or mail gateway. One well-rehearsed procedure is worth more than ten improvised ones.
HIT Communications has operated enterprise networks and communications for more than 30 years across Latin America, the United States and Europe. We see vulnerability response as part of one connected environment: network, servers, identity, voice and cloud.
Our cybersecurity services combine a 24/7 SOC, SIEM and managed detection and response to find web shells and other persistence, validate indicators of compromise and guide containment while patches are tested. Our IT managed services keep inventories, patching and backups under control so that an advisory like this one becomes a routine change, not a crisis. And our multi-operator connectivity and SD-WAN designs provide segmented, redundant paths that limit the reach of any single compromised host.
If your organization runs on-premises SharePoint, Exchange or other self-hosted collaboration systems, we can help you confirm exposure, hunt for compromise and set up the monitoring that shortens the next response.
CVE-2026-65660 shows how a fixed vulnerability can still cause a breach: the severity label was revised late, the exploit chains two weaknesses, and a web shell outlives the patch. The right response is to patch, then hunt, then harden and monitor.
If you are not sure which SharePoint servers are exposed, whether they were checked after September 24, or whether anyone is watching their logs around the clock, now is the time to find out. Contact HIT Communications and schedule a conversation with our team to review your exposure and your detection and response approach.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch