Skip to content
Rush Commerce
Software & Dev4 min read

SharePoint CVE-2026-65660: three days to patch

CISA added SharePoint CVE-2026-65660 to KEV on September 25 with a September 28 deadline. Microsoft shipped the fix August 11. Check your build number.

SharePoint CVE-2026-65660 went from a patched August bug to an actively exploited one on September 25, and the federal deadline is September 28. Microsoft shipped the fix in the August 11 cycle. If you run SharePoint Server on-prem and nobody has applied a cumulative update since summer, you are inside the window that matters.

What actually happened

CISA added CVE-2026-65660 to the Known Exploited Vulnerabilities catalog on September 25, alongside a MikroTik RouterOS flaw. The NVD record carries CISA's own SSVC assessment: exploitation active, technical impact total.

The bug is code injection (CWE-94) in SharePoint's ToolPane component. CVSS 8.8, vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — network-reachable, low attack complexity, low privileges required, no user interaction, and confidentiality, integrity and availability all rated High. "Low privileges" means any authenticated account on the site. That is a normal employee, a contractor, or one phished login.

Here is the part that will cost you time. The Hacker News reported that Microsoft's advisory page titles CVE-2026-65660 a spoofing vulnerability and scores it 6.5, while the CVE record Microsoft publishes to NVD describes an authorized attacker executing code over a network and scores it 8.8. Same vendor, same CVE, two different severities. The researcher credited is Dinh Ho Anh Khoa of Viettel Cyber Security, and exploit code is public.

The patched builds, straight from the NVD record: SharePoint Enterprise Server 2016 at 16.0.5565.1001 or later, SharePoint Server 2019 at 16.0.10417.20198 or later, Subscription Edition at 16.0.19725.20522 or later. SharePoint 2013 is out of support and is not getting a fix.

Why a vendor severity mismatch matters for your business

Your patch queue is probably sorted by the wrong number. If your process is "anything 7.0 and above gets expedited," a 6.5 on the vendor's advisory page sailed past you in August. The 8.8 lives in a record most people never open. One CVE, two scores, and the one your tooling reads is the lower one.

Go look at the build number, not the patch log. SharePoint cumulative updates get deferred more than almost anything else on-prem, usually because someone once had a farm break on one. Pull the current build from Central Administration and compare it to the three numbers above. The patch log tells you what someone intended; the build number tells you what is running.

Three days is CISA's number, not yours. The BOD 26-04 deadline binds federal agencies. It is not a suggestion aimed at you, but it is the best free signal available for "somebody is using this right now." When a CVE hits KEV, it jumps the queue regardless of what the vendor advisory called it in August.

Assume the authenticated account is already available. The privilege bar here is membership, not admin. If your SharePoint has external sharing turned on, guest accounts, or a service account whose password has not rotated since the farm was built, the attacker does not need to escalate to anything. Patch, then audit who actually holds site membership.

If your SharePoint is managed by an MSP, today's email is one line: what build are we on, and when does the August cumulative update land.

Key takeaways

  • CVE-2026-65660 is a CVSS 8.8 code injection flaw (CWE-94) in SharePoint's ToolPane component, exploitable by any authenticated user
  • Microsoft's advisory page labels it spoofing at 6.5; the CVE record Microsoft publishes to NVD calls it code execution at 8.8
  • Microsoft shipped the fix on August 11, 2026; CISA added it to KEV on September 25 with a September 28 federal deadline
  • Patched builds: 2016 at 16.0.5565.1001+, 2019 at 16.0.10417.20198+, Subscription Edition at 16.0.19725.20522+
  • SharePoint 2013 is unsupported and will not receive a fix
  • Exploit code is public; CISA's SSVC assessment records exploitation as active with total technical impact
  • If your patch triage is driven by a CVSS threshold read off the vendor page, this is exactly the shape of bug it misses

Who reads your CVE feed? If the honest answer is nobody, that is the finding, not the vulnerability. We wire KEV into the patch process for the systems we run, so a severity re-rating three states away still reaches the person with the console open. Ask for a patch-cadence review, or see how we handle infrastructure we did not build.

Sources: CISA KEV alert, September 25 2026, NVD CVE-2026-65660, The Hacker News.

  • #sharepoint
  • #cve-2026-65660
  • #cisa-kev
  • #patch-management
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.