CISA put SharePoint on KEV. August's ticket said spoofing. Microsoft now says RCE.
CVE-2026-65660 is CWE-94 authenticated code injection. Catalog 2026.09.25, due 28 September. Microsoft had reliable evidence of attacks as of 25 September.
Bottom line up front
CONFIRMED CISA added CVE-2026-65660 to the Known Exploited Vulnerabilities catalog on 25 September 2026. Catalog version 2026.09.25 (released 25 September 18:58 UTC, count 1726). Three new rows since [yesterday’s WSO2 Daily Top](/posts/2026-09-25-wso2-cve-2026-5430-kev/). Federal due date is 28 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes. CISA-ADP SSVC on the NVD record, stamped 24 September 00:00 UTC: exploitation active, automatable no, technical impact total.
The product set is on-premises Microsoft SharePoint Server — Enterprise Server 2016, Server 2019, and Subscription Edition. The vendor bug is CWE-94 code injection. Microsoft’s live advisory titles it Remote Code Execution, CVSS 3.1 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. An authorized, low-privileged network attacker can execute code. No user click.
Do not collapse three facts.
- The August ticket is the wrong severity. Microsoft published this CVE on 11 August 2026 as SharePoint spoofing, CVSS 6.5, integrity and availability none. On 27 August it recast the same record to RCE at 8.8 and labelled the revision informational. CWE-94 did not change. Farms that closed “Important spoofing, Exploitation Less Likely” in August still need the August 11 security updates, and they need them against a KEV clock.
- Microsoft now says the attacks are real. The exploitability table on the advisory still shows the original-publication line: publicly disclosed No, exploited No, exploitation less likely. A separate Current Exploitation Status line, dated 25 September 2026, states Microsoft had reliable evidence of observed attacks. CISA’s KEV add is the same day. That is vendor confirmation, not a tracker restating CISA.
- Authenticated is the CVE. Anonymous is a chain, and only on a stale farm. CVE-2026-65660 itself is
PR:L. CCCS AL26-023 (24 September) and Viettel’s 22 September write-up both describe a separate, already-patched delivery path that can make the same primitive pre-authentication on sites that still allow anonymous viewing and that missed a 9 June fix. Hunt both. Do not write the KEV row as unauthenticated RCE.
This is not a re-run of [Thursday’s WordPress Core include](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). WordPress CVE-2026-87902 did land in this freeze — sequenced below. [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) is due tomorrow.
| Fact | Record |
|---|---|
| CVE | CVE-2026-65660 |
| Product | SharePoint Enterprise Server 2016; Server 2019; Subscription Edition (on-prem) |
| Vendor advisory | MSRC, released 11 August 2026, last updated 25 September 2026 |
| Vendor score | CVSS 3.1 8.8 (Important) |
| CWE | CWE-94 |
| KEV catalog | 2026.09.25, count 1726 |
| Added / due | 25 September / 28 September 2026 |
| Exploitation | CONFIRMED as KEV; Microsoft “reliable evidence” 25 Sep; CCCS AL26-023 24 Sep |
| Ransomware use | Unknown |
| Named CISA actor | None |
| OT / process impact | None claimed |
What happened
CISA published two 25 September KEV alerts. The JSON freeze we retrieved is catalog 2026.09.25, dateReleased 2026-09-25T18:58:16Z, count 1726 (yesterday’s WSO2 Daily Top froze 2026.09.24 at 1723). The two-CVE alert names SharePoint CVE-2026-65660 and MikroTik RouterOS CVE-2026-67279. A separate one-CVE alert names WordPress Core CVE-2026-87902, which we already assessed on [24 September](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). All three rows are due 28 September. NVD last-modified 26 September 04:17 UTC.
The 65660 KEV row: vendor Microsoft, product SharePoint, CWE-94, ransomware Unknown, forensic triage Yes. Notes point at the MSRC advisory, BOD 26-04, and NVD.
Microsoft’s own advisory is the technical close:
- Impact: remote code execution. Weakness: CWE-94.
- Executive summary: improper control of generation of code in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- FAQ: if multiple update packages are offered for the installed product, apply all of them, in any order. SharePoint Server 2016 and SharePoint Enterprise Server 2016 share the same KB.
- Current exploitation status (25 September): Microsoft had reliable evidence of observed attacks. That sentence is not the original-publication exploitability table.
CCCS AL26-023, dated 24 September — one day before the KEV row — is the national-CERT corroboration. It restates CWE-94, authenticated arbitrary code execution, and the chain: with other SharePoint vulnerabilities, pre-authentication RCE is possible on servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates face elevated risk. CCCS also records that SharePoint Enterprise Server 2016 and Server 2019 are end of life as of 15 July 2026. The August patches still exist; the support clock does not.
Fixed builds in CCCS, matching Microsoft’s affected-data ranges on NVD:
| Product | Close |
|---|---|
| SharePoint Enterprise Server 2016 | 16.0.5565.1001 |
| SharePoint Server 2019 | 16.0.10417.20198 |
| SharePoint Server Subscription Edition | 16.0.19725.20522 |
NVD’s CPE block is messier than that table: Subscription Edition has versionEndExcluding 16.0.19725.20522; the 2016 Enterprise and 2019 CPEs are unversioned product matches. Treat the vendor/CCCS build numbers as the patch instruction. Treat extra CPE shape as ASSESSED NVD encoding, not a second Microsoft product list.
SharePoint in Microsoft 365 is not in the affected-product list. Absence from the advisory is not a statement that the service was never vulnerable. It is not claimed here.
The public exploitation telemetry that is not CISA’s unpublished evidence:
- Previdian, 24 September, with a 25 September update. One SharePoint honeypot, 12 POST requests around 12:00 UTC on 24 September, single source 169.150.248.21 (AS212238, Datacamp Limited). Paths under
/_layouts/15/AddGallery.aspxand/_layouts/15/designgallery.aspx, queryDisplayMode=Edit, no Cookie or Authorization header. Two complementary bodies. 25 September update: exploitation creates a webshell at/_layouts/15/sphealth.aspx. Embedded assembly nameswt3k3sij.dlland24e5mo4s.dll(PE32 x86, CLR header). Previdian classifies the burst as an attempted pre-authentication chain, dependent on anonymous viewing plus the June delivery bug plus 65660. It does not claim a named victim, recover the decrypted final assembly, or identify an operator. - Viettel Cyber Security (Dinh Ho Anh Khoa), 22 September, via The Hacker News the same day: SafeControls allowlist bypass in ToolPane web-part markup. The Hacker News, writing before KEV, stated no in-the-wild reports and that the flaw was not in the catalog. That sentence is dated. Do not recycle it as current.
RWP is not reproducing markup, deserialization gadget construction, or request bodies.
Why it matters
On-prem SharePoint is still the document and workflow plane for a large share of enterprises that never finished the Microsoft 365 move — including shops whose 2016 and 2019 farms went end-of-life in July and are still serving pages. A low-privileged authenticated RCE on that plane is not “a spoofing ticket from August.”
Two operational lies will show up in tickets this weekend:
- “We closed 65660 as Important spoofing in August.” The original MSRC title, the 6.5 vector with
I:N/A:N, and the “Exploitation Less Likely” row are still on the page. They describe publication day, not 25 September. CWE-94 was always code injection. The 27 August recast was labelled informational, which is how a lot of patch programs never reopened the ticket. KEV due Monday is the reopen. - “KEV says authorized, so internet-facing anonymous sites are fine.” The KEV short description is correct about the CVE: authorized attacker, code injection, network. The chain CCCS and Viettel describe is a different ticket — anonymous viewing plus a June-patched delivery path plus 65660. Previdian’s 24 September burst used that shape. Inventory anonymous access and the June updates as well as the August build number. SSVC automatable no is CISA-ADP’s statement about the authenticated CVE, not a census that nobody will script the chain.
BOD 26-04’s forensic-triage flag means the ticket is not closed when the build integer ticks. A farm that has been reachable, unpatched, and (for the chain) anonymously viewable through September may already have a layout-directory webshell. The patch does not rewind that. Microsoft’s notes do not say the update removes a foothold already taken.
No public victim count. CISA, Microsoft, CCCS, Previdian, Viettel, and The Hacker News do not name an actor, a ransomware affiliate, or a confirmed customer breach. Previdian’s one-IP honeypot burst is CONFIRMED as sensor telemetry, not a victim list. RWP is not treating ToolShell’s 2025 Chinese-nexus history as attribution for this CVE. Khoa researched both. That is a researcher overlap, not a campaign merge.
This is IT collaboration infrastructure. A compromised SharePoint farm at an industrial company is not confirmed OT compromise and is not process impact.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| SharePoint Enterprise Server 2016 below 16.0.5565.1001 | In scope | CONFIRMED vendor / CCCS / NVD |
| SharePoint Server 2019 below 16.0.10417.20198 | In scope | CONFIRMED vendor / CCCS / NVD |
| SharePoint Server Subscription Edition below 16.0.19725.20522 | In scope | CONFIRMED vendor / CCCS / NVD |
| Same trains at or above those builds, with all offered packages applied | Vendor close for this CVE | CONFIRMED vendor FAQ |
| SharePoint Server 2016 / 2019 still running after 15 July 2026 EOL | In scope if below the August build; unsupported going forward | CONFIRMED CCCS lifecycle |
| SharePoint 2013 | Viettel says the primitive exists; Microsoft does not list it; out of support since April 2023 | ASSESSED researcher; no vendor patch |
| SharePoint in Microsoft 365 | Not in the affected list | UNKNOWN / not claimed |
| Sites allowing anonymous viewing, missing the 9 June delivery fix | Elevated to a pre-auth chain | CONFIRMED as CCCS/Viettel/Previdian description of a separate bug |
| Named victims | None published | UNKNOWN |
| OT / ICS / process | Not claimed | No evidence |
| CISA ransomware field | Unknown | CONFIRMED catalog |
Internet-reachable on-prem farms, Central Administration, and any site with anonymous viewing enabled are the inventory unit. That is configuration, not an exploit recipe.
Technical context
RWP is not reproducing ToolPane markup, Register-directive quote injection, or deserializer payloads.
What the primary records give defenders:
- Primitive. Network-reachable code injection (CWE-94) in on-prem SharePoint. Low privileges. No user interaction. Authenticated. Vendor impact RCE.
- Prerequisite for the CVE as scored. An affected SharePoint Server build and an authorized (low-privileged) attacker path to the vulnerable handling. Microsoft’s vector is
PR:L. - Prerequisite for the pre-auth chain, which is not the KEV short description. Anonymous viewing still enabled, plus the June 2026 delivery-path fix missing, plus 65660 unpatched. Viettel did not assign a CVE to the June issue. CCCS describes it as “chained with other SharePoint vulnerabilities.”
- Not claimed by Microsoft. Unauthenticated RCE as the 65660 primitive. SharePoint Online in the affected list. A named actor. Ransomware-Known.
- Follow-on that Previdian observed, not that CISA documented. Two-stage POST burst, layout-path webshell
sphealth.aspx, embedded CLR assemblies. Treat as CONFIRMED honeypot telemetry from one sensor, not as a global implant catalog.
ATT&CK mapping for what is stated:
- Exploit public-facing application (T1190) against on-prem SharePoint.
- Server software component / web shell (T1505.003) for the Previdian
sphealth.aspxpath. - Valid accounts (T1078) on the authenticated CVE path.
Follow-on that is not claimed: a named APT, ransomware-Known, confirmed machine-key theft at a named customer, or OT/process impact. Older ToolShell traffic centered on ToolPane.aspx; Previdian notes hunting only that endpoint would miss AddGallery.aspx / designgallery.aspx. That is a detection gap, not a statement that this CVE is ToolShell.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
In KEV, added 25 Sep, due 28 Sep, catalog 2026.09.25 count 1726 | CONFIRMED | CISA two-CVE alert + JSON |
| Exploitation in the wild | CONFIRMED as KEV criterion and as Microsoft 25 Sep status | CISA; MSRC; CISA-ADP SSVC active |
| CCCS aware of active exploitation, 24 Sep | CONFIRMED as national CERT | AL26-023 |
| Previdian 12-request honeypot burst 24 Sep; webshell path 25 Sep | CONFIRMED as sensor telemetry | Previdian |
| CWE-94, CVSS 8.8, PR:L, on-prem 2016/2019/SE | CONFIRMED | MSRC; NVD |
| Original August label spoofing / 6.5; 27 Aug recast RCE / 8.8 | CONFIRMED as vendor revision history | MSRC; THN 22 Sep; NVD |
| Victim count / actor | UNKNOWN | No named set in CISA, Microsoft, CCCS, Previdian |
| Ransomware use | Unknown | Catalog field |
| Forensic triage required | Yes | Catalog field |
| SSVC active / automatable no / total | CONFIRMED as CISA-ADP, 24 Sep stamp | NVD |
| Pre-auth chain on anonymous + June-unpatched | CONFIRMED as described by CCCS/Viettel; observed as attempt by Previdian | Not the KEV short description |
| OT / physical-process impact | Not claimed | No evidence |
High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 8.8, CWE-94, the three product trains and close builds, forensic-triage flag, ransomware Unknown, Microsoft’s 25 September exploitation sentence, the August spoofing-to-RCE recast, CCCS EOL date, Previdian’s 24 September timestamp and webshell path. Moderate confidence that internet-reachable on-prem farms, especially those still on 2016/2019 after July EOL, are the dominant real-world condition (product role + CCCS guidance; no public census). Low confidence on CISA’s unpublished exploitation evidence, on any victim identity, on whether SharePoint 2013 is practically exploitable in 2026, and on whether the August build displaces a webshell already written.
What defenders should do
- Inventory on-prem farms by product train and build, not “we are on Microsoft 365.” Enterprise 2016, 2019, Subscription Edition, internet exposure, anonymous-viewing setting, and whether Central Administration is reachable from untrusted networks. Record exposure for BOD 26-04. 2016 and 2019 past 15 July are still this CVE if below the August build; they are also a migration ticket.
- Preserve, then patch, then assume the layout directory was already written. Snapshot IIS/SharePoint ULS, web-application anonymous policy, web-part gallery changes, machine-key access, and
%COMMONPROGRAMFILES%/_layoutslistings before you roll the August 11 packages. Apply all MSRC-offered packages for the installed product. Confirm the running build is at or above 16.0.5565.1001 / 16.0.10417.20198 / 16.0.19725.20522. CISA’s notes do not say the patch removes a foothold already taken.
- Hunt the 24–25 September shape, not only ToolPane.aspx. POST to
AddGallery.aspxanddesigngallery.aspx(including repeated/_layouts/prefixes) withDisplayMode=Edit. New file/_layouts/15/sphealth.aspx. Unexpected web-part modifications. AMSI/Defender detections on SharePoint worker processes. Assemblies namedwt3k3sij.dllor24e5mo4s.dll— Previdian published SHA-256d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742anda151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1. Source IP 169.150.248.21 is this sensor’s burst, not a blocklist of the campaign. CCCS also flags suspicious machine-key access and deserialization/web-shell behaviour.
- Close the chain, not only the CVE row. Disable anonymous viewing where it is not a documented business requirement. Confirm the June 2026 SharePoint security updates that Viettel and CCCS treat as the anonymous-delivery close. Enable AMSI integration for SharePoint web applications in Full Mode where operationally feasible (CCCS). Restrict Central Administration.
- Do not let the August title drive the scanner severity. If your vuln workflow still keys 65660 as spoofing 6.5, override it to KEV / RCE 8.8 / forensic triage. The original exploitability table is not the 25 September status line.
- Sequence the rest of this freeze, then yesterday’s. Same catalog: CVE-2026-87902 (WordPress Core, already [Thursday’s Daily Top](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/), now KEV, forensic triage Yes, due 28 September) and CVE-2026-67279 (MikroTik RouterOS SSH rekey skips authentication, CWE-841, chained to already-KEV CVE-2026-86060, forensic triage No, due 28 September; vendor close 6.49.21 / 7.23.4 / 7.24.2). Due tomorrow: [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe Commerce CVE-2026-71362.
This is not an exploitation guide. Use Microsoft’s security updates table.
RWP assessment
Score 8.9. Same-day vendor confirmation and KEV add, a three-day BOD 26-04 clock with forensic triage, on-prem SharePoint as the enterprise document plane, and an August spoofing label that will leave farms on the wrong ticket. That is the highest-leverage new row in catalog 2026.09.25.
It outranks CVE-2026-87902 (WordPress Core, same freeze, same due date, unauthenticated include, already exploited when we published Thursday) as a daily because the WordPress primitive is not new today — the KEV row is a clock on a story we already shipped. It outranks CVE-2026-67279 (MikroTik RouterOS, same freeze) because 67279 is the missing first half of CERT Polska’s MikroTrick chain; CVE-2026-86060 has been on KEV since 10 September, and we already sequenced that chain on 9 and 11 September. A second RouterOS row is a real federal clock. It is not a first look. It outranks Kiteworks’ 25 September precautionary customer shutdown (federal intelligence, no CVE, vendor says no indication of compromise, current release 9.5.1) because evidence quality for a confirmed vulnerability is poor even though the operational ask — take MFT offline — is unusual. It outranks a second day on [WSO2 5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) because tomorrow’s due date is not a new technical finding.
The failure mode to sand down is “August said spoofing” and its twin, “authorized, so the anonymous site is fine.” If the running build is below the table and the farm still serves pages, you are in CISA’s denominator. If you only grepped for ToolPane.aspx, you inventoried last year’s path.
What we are watching
- Whether Microsoft revises the original-publication exploitability table to match the 25 September current-status line.
- Whether ransomware-use flips off Unknown.
- Whether Microsoft, CCCS, or Previdian names a victim class or an actor.
- Monday’s close rate on 65660, 67279, and 87902, and Sunday’s close rate on 5430 and 71362.
- Whether Kiteworks publishes a CVE, a patch, or a confirmed intrusion after this weekend’s shutdown window.
- Any attempt to treat a compromised SharePoint farm at an industrial company as OT impact without process evidence.
Sources
- CISA — Adds two KEV (25 September 2026)
- CISA — Adds one KEV, CVE-2026-87902 (25 September 2026)
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Microsoft — CVE-2026-65660 Security Update Guide
- NVD — CVE-2026-65660
- CVE.org — CVE-2026-65660
- CCCS — AL26-023 (24 September 2026)
- Previdian — two-stage SharePoint exploitation attempts (24 September 2026)
- The Hacker News — SharePoint spoofing listing enables authenticated RCE (22 September 2026)
- Viettel Cyber Security — SharePoint CVE-2026-65660
- BleepingComputer — CISA warns of SharePoint, WSO2, Adobe Commerce flaws (25 September 2026)
- CVE.org — CVE-2026-67279
- MikroTik — September 2026 vulnerability
- CERT Polska — MikroTrick technical analysis
- Kiteworks — precautionary shutdown advisory (25 September 2026)
- [RWP Daily Top, 25 September 2026 — WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/)
- [RWP Daily Top, 24 September 2026 — WordPress CVE-2026-87902](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/)
- [RWP Daily Top, 23 September 2026 — F5 CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/)
- [RWP Daily Top, 11 September 2026 — PaperCut](/posts/2026-09-11-papercut-ai-agent-campaign/)
Sources
- CISA — Adds two KEV including CVE-2026-65660
- CISA — Adds one KEV CVE-2026-87902
- CISA — KEV JSON feed catalog 2026.09.25
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Microsoft — CVE-2026-65660 Security Update Guide
- NVD — CVE-2026-65660
- CVE — CVE-2026-65660
- CCCS — AL26-023 SharePoint CVE-2026-65660
- Previdian — Two-stage SharePoint exploitation attempts
- The Hacker News — SharePoint spoofing listing enables authenticated RCE
- Viettel Cyber Security — SharePoint CVE-2026-65660
- BleepingComputer — CISA warns of SharePoint, WSO2, Adobe Commerce flaws
- CISA — CVE-2026-67279 KEV row
- MikroTik — September 2026 vulnerability
- CERT Polska — MikroTrick technical analysis
- Kiteworks — Precautionary shutdown advisory