Microsoft: Microsoft SharePoint Server CVE-2026-65660 Actively Exploited: Critical RCE Vulnerability Threatens Unpatched Systems

Microsoft: Microsoft SharePoint Server CVE-2026-65660 Actively Exploited: Critical RCE Vulnerability Threatens Unpatched Systems

Critical Microsoft SharePoint RCE Vulnerability (CVE-2026-65660) Actively Exploited in the Wild

A critical remote code execution (RCE) vulnerability, CVE-2026-65660, has been confirmed as actively exploited in enterprise environments, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog. The flaw affects Microsoft SharePoint Server 2016, 2019, and Subscription Edition, allowing authenticated, low-privileged users to execute arbitrary code on vulnerable systems.

Initially misclassified as a spoofing issue, further analysis revealed the vulnerability stems from improper handling of Register directives in SharePoint’s SafeControls mechanism. Attackers can inject malicious directives by exploiting unescaped quotes in web-part markup, enabling the registration of arbitrary .NET classes. This flaw permits the deserialization of attacker-supplied XAML payloads via XamlServices.Parse(), leading to RCE within the SharePoint application pool.

Public proof-of-concept (PoC) code has accelerated exploitation, with threat actors deploying in-memory webshells to evade detection and establish persistence. The vulnerability can also be chained with other exploits, such as a previously patched authentication bypass (fixed June 9, 2026), to achieve pre-authentication RCE on servers with anonymous access enabled.

Threat Landscape & Targeting

While no specific advanced persistent threat (APT) group has been publicly attributed to these attacks, historical patterns suggest Chinese state-backed actors and other sophisticated groups are likely leveraging the flaw. Previous SharePoint RCE vulnerabilities have been exploited for initial access, lateral movement, and data exfiltration, particularly in government, defense, finance, and critical infrastructure sectors.

Opportunistic cybercriminals are also scanning for vulnerable SharePoint instances, with automated tools facilitating mass exploitation. The global prevalence of SharePoint especially in North America, Europe, and Asia-Pacific makes organizations across these regions prime targets.

Mitigation & Detection

Microsoft released a security update on August 11, 2026, addressing the flaw in supported SharePoint versions. Organizations must patch immediately and disable anonymous access where unnecessary. Security teams should monitor for:

  • Malformed Register directives in web-part markup
  • Unexpected low-privilege logins and anomalous process creation
  • Outbound C2 connections from SharePoint servers
  • In-memory webshells via memory analysis

Unsupported SharePoint Server 2013 instances should be upgraded or isolated to prevent exploitation. Behavioral monitoring for deserialization activity and network segmentation can further limit impact.

Source: https://www.rescana.com/post/microsoft-sharepoint-server-cve-2026-65660-actively-exploited-critical-rce-vulnerability-threatens-unpatched-systems

Microsoft_SharePoint cybersecurity rating report: https://www.rankiteo.com/company/microsoft_sharepoint

"id": "MIC1790584378",
"linkid": "microsoft_sharepoint",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Government',
                                     'Defense',
                                     'Finance',
                                     'Critical Infrastructure'],
                        'location': ['North America', 'Europe', 'Asia-Pacific'],
                        'type': 'Enterprise organizations'}],
 'attack_vector': 'Authenticated low-privilege user exploitation via web-part '
                  'markup injection',
 'data_breach': {'data_exfiltration': 'Possible (not confirmed)'},
 'date_resolved': '2026-08-11',
 'description': 'A critical remote code execution (RCE) vulnerability, '
                'CVE-2026-65660, has been confirmed as actively exploited in '
                'enterprise environments. The flaw affects Microsoft '
                'SharePoint Server 2016, 2019, and Subscription Edition, '
                'allowing authenticated, low-privileged users to execute '
                'arbitrary code on vulnerable systems. Attackers can inject '
                'malicious directives by exploiting unescaped quotes in '
                'web-part markup, enabling the registration of arbitrary .NET '
                'classes and deserialization of attacker-supplied XAML '
                'payloads via XamlServices.Parse(), leading to RCE within the '
                'SharePoint application pool.',
 'impact': {'brand_reputation_impact': 'High (critical vulnerability actively '
                                       'exploited)',
            'data_compromised': 'Potential data exfiltration (sensitivity not '
                                'specified)',
            'operational_impact': 'Potential unauthorized code execution, '
                                  'persistence via in-memory webshells, and '
                                  'lateral movement',
            'systems_affected': 'Microsoft SharePoint Server 2016, 2019, '
                                'Subscription Edition, and unsupported '
                                'SharePoint Server 2013'},
 'initial_access_broker': {'backdoors_established': 'In-memory webshells'},
 'investigation_status': 'Ongoing (public PoC available, active exploitation '
                         'confirmed)',
 'motivation': ['Initial access',
                'Lateral movement',
                'Data exfiltration',
                'Financial gain'],
 'post_incident_analysis': {'corrective_actions': ['Patch management',
                                                   'Disable anonymous access',
                                                   'Network segmentation',
                                                   'Enhanced monitoring for '
                                                   'deserialization activity'],
                            'root_causes': 'Improper handling of Register '
                                           'directives in SharePoint’s '
                                           'SafeControls mechanism, allowing '
                                           'unescaped quotes in web-part '
                                           'markup to enable arbitrary .NET '
                                           'class registration and XAML '
                                           'payload deserialization'},
 'recommendations': ['Patch immediately using Microsoft’s August 11, 2026 '
                     'security update',
                     'Disable anonymous access where unnecessary',
                     'Monitor for malformed Register directives and '
                     'deserialization activity',
                     'Upgrade or isolate unsupported SharePoint Server 2013 '
                     'instances',
                     'Implement behavioral monitoring and network '
                     'segmentation'],
 'references': [{'source': 'U.S. Cybersecurity and Infrastructure Security '
                           'Agency (CISA)',
                 'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog'}],
 'response': {'containment_measures': ['Disable anonymous access',
                                       'Network segmentation',
                                       'Monitor for malformed Register '
                                       'directives'],
              'enhanced_monitoring': ['Monitor for unexpected low-privilege '
                                      'logins',
                                      'Anomalous process creation',
                                      'Outbound C2 connections',
                                      'In-memory webshells via memory '
                                      'analysis'],
              'network_segmentation': 'Recommended',
              'remediation_measures': ['Apply Microsoft security update '
                                       '(August 11, 2026)',
                                       'Upgrade or isolate unsupported '
                                       'SharePoint Server 2013 instances']},
 'threat_actor': ['Chinese state-backed actors',
                  'Opportunistic cybercriminals'],
 'title': 'Critical Microsoft SharePoint RCE Vulnerability (CVE-2026-65660) '
          'Actively Exploited in the Wild',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-65660 (improper handling of Register '
                            'directives in SharePoint’s SafeControls '
                            'mechanism)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.