FALCONINTERNET

CVE-2026-65660: SharePoint's 'Spoofing' Bug Enables Code Execution

Security
CVE-2026-65660: SharePoint's 'Spoofing' Bug Enables Code Execution

On August 11, 2026, Microsoft shipped a security update for SharePoint Server and called the accompanying vulnerability a spoofing issue, rating it 6.5 (Important, but not urgent). That label was wrong. The CVE record was quietly updated on September 11 to describe remote code execution. The National Vulnerability Database scores it 8.8. And on September 25, CISA added CVE-2026-65660 to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively exploiting it right now.

That six-week gap between patch and alarm, created in large part by a mislabeled severity rating, is the kind of window ransomware operators live in.

How the ToolPane code injection works

CVE-2026-65660 lives in how on-premises SharePoint Server handles web-part markup. The ToolPane component reconstructs .NET Register directives by writing attribute values between double quotes, but it never escapes any quotes inside those attribute values. An authenticated attacker can smuggle additional directives through those unescaped quotes, registering arbitrary .NET classes after SharePoint's SafeControls filter has already run its check but before the control loads. Once an arbitrary class is registered, the attacker calls XamlServices.Parse() to trigger deserialization and land code execution on the server.

In short: SharePoint checks whether a class is safe, then loads a different class than the one it checked. The type-check runs; the injected directive wins.

Microsoft's advisory described this as spoofing with "no impact to integrity or availability." The NVD entry assigns High confidentiality, High integrity, and High availability impact. Those are not the same thing.

The exploit chain that skips authentication

On its own, CVE-2026-65660 requires an authenticated session: an attacker needs a valid SharePoint account to send the malicious web-part payload. That is a meaningful bar for external attackers, but not an insurmountable one. Many organizations expose SharePoint to contractors, partners, or customers with low-privilege accounts. Others run SharePoint with anonymous access enabled for public-facing intranets or document portals.

Where anonymous access is configured, Previdian's threat intelligence team observed attackers chaining CVE-2026-65660 with a separate anonymous delivery bug documented by security researcher vcslab. That chain eliminates the authentication requirement entirely: an unauthenticated external attacker can deliver the exploit payload, which then triggers the code-injection flaw and installs an encrypted loader for persistent server control. The combined attack chain is effectively critical severity.

Who is at risk

Affected: On-premises installations of SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. SharePoint Server 2013 is also vulnerable, and no patch will be issued because Microsoft ended support in April 2023.

Not affected: SharePoint Online, the cloud-hosted version delivered through Microsoft 365. If your organization uses SharePoint exclusively through a browser pointing at sharepoint.com, you are not exposed to this flaw. Microsoft manages patching on the cloud side.

The risk is highest for organizations that never applied the August 11 Patch Tuesday updates, and given that many administrators triaged this as a 6.5 spoofing bug, that is a larger group than it should be. The Canadian Centre for Cyber Security issued a formal advisory on September 24, the day before CISA acted, suggesting exploitation activity was confirmed across multiple governments' threat-intelligence feeds before the public alarm went out.

Patching and mitigation steps

  • Apply the August 11 security updates. SharePoint Server 2016, 2019, and Subscription Edition all have patches available. If your SharePoint is behind on cumulative updates, this is the reason to catch up today.
  • Check for signs of compromise first. Before patching an actively exploited server, look for unexpected files in the SharePoint web root, new scheduled tasks or services running under the application pool account, and outbound connections from the SharePoint server to unfamiliar hosts. Patching closes the door; it does not evict an attacker already inside.
  • Disable anonymous access if you do not need it. Most on-premises SharePoint deployments do not require anonymous access. Turning it off eliminates the unauthenticated attack chain even before the patch is applied, and is a sound default posture anyway.
  • Audit low-privilege accounts. If external parties have SharePoint accounts, confirm they are necessary and their permissions are scoped to the minimum required. The authenticated attack path works even without the anonymous chain.
  • SharePoint 2013: There is no patch. It needs to be isolated from external network access or migrated off. There is no supported remediation short of those two options.

Microsoft's severity rating understated the flaw

Microsoft's Security Response Center uses its own scoring methodology that sometimes diverges significantly from CVSS. The 6.5 spoofing rating almost certainly suppressed how quickly administrators prioritized this patch. A CVSS 8.8 RCE label would have drawn immediate attention. Most patch-management platforms display Microsoft's score first, and a defender who scanned that number and moved on missed the real signal.

It is worth building a habit of cross-checking any Microsoft patch that describes spoofing or information disclosure against the NVD entry and the actual CVE record, particularly for services exposed to the internet or to authenticated external users. The CVE record and the advisory sometimes tell different stories, and the NVD score is typically the more conservative and more accurate signal.

At Falcon Internet, this is exactly the kind of situation our 24x7x365 NOC monitoring is built to catch: a patch that looked lower-priority until exploitation suddenly made it urgent. The August 11 update window did not feel critical at the time. The September 25 CISA KEV listing should close that debate.

Need this handled instead of explained?

We do this for a living — talk to an engineer about your setup.