Daily Top · Vulnerabilities / Microsoft

CISA put SharePoint on KEV. August's ticket said spoofing. Microsoft now says RCE.

CVE-2026-65660 is CWE-94 authenticated code injection. Catalog 2026.09.25, due 28 September. Microsoft had reliable evidence of attacks as of 25 September.

RWP Ventures · 2026-09-26 · event 2026-09-25 · 16 min read · priority 8.9

Bottom line up front

CONFIRMED CISA added CVE-2026-65660 to the Known Exploited Vulnerabilities catalog on 25 September 2026. Catalog version 2026.09.25 (released 25 September 18:58 UTC, count 1726). Three new rows since [yesterday’s WSO2 Daily Top](/posts/2026-09-25-wso2-cve-2026-5430-kev/). Federal due date is 28 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes. CISA-ADP SSVC on the NVD record, stamped 24 September 00:00 UTC: exploitation active, automatable no, technical impact total.

The product set is on-premises Microsoft SharePoint Server — Enterprise Server 2016, Server 2019, and Subscription Edition. The vendor bug is CWE-94 code injection. Microsoft’s live advisory titles it Remote Code Execution, CVSS 3.1 8.8 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. An authorized, low-privileged network attacker can execute code. No user click.

Do not collapse three facts.

  1. The August ticket is the wrong severity. Microsoft published this CVE on 11 August 2026 as SharePoint spoofing, CVSS 6.5, integrity and availability none. On 27 August it recast the same record to RCE at 8.8 and labelled the revision informational. CWE-94 did not change. Farms that closed “Important spoofing, Exploitation Less Likely” in August still need the August 11 security updates, and they need them against a KEV clock.
  2. Microsoft now says the attacks are real. The exploitability table on the advisory still shows the original-publication line: publicly disclosed No, exploited No, exploitation less likely. A separate Current Exploitation Status line, dated 25 September 2026, states Microsoft had reliable evidence of observed attacks. CISA’s KEV add is the same day. That is vendor confirmation, not a tracker restating CISA.
  3. Authenticated is the CVE. Anonymous is a chain, and only on a stale farm. CVE-2026-65660 itself is PR:L. CCCS AL26-023 (24 September) and Viettel’s 22 September write-up both describe a separate, already-patched delivery path that can make the same primitive pre-authentication on sites that still allow anonymous viewing and that missed a 9 June fix. Hunt both. Do not write the KEV row as unauthenticated RCE.

This is not a re-run of [Thursday’s WordPress Core include](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). WordPress CVE-2026-87902 did land in this freeze — sequenced below. [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) is due tomorrow.

FactRecord
CVECVE-2026-65660
ProductSharePoint Enterprise Server 2016; Server 2019; Subscription Edition (on-prem)
Vendor advisoryMSRC, released 11 August 2026, last updated 25 September 2026
Vendor scoreCVSS 3.1 8.8 (Important)
CWECWE-94
KEV catalog2026.09.25, count 1726
Added / due25 September / 28 September 2026
ExploitationCONFIRMED as KEV; Microsoft “reliable evidence” 25 Sep; CCCS AL26-023 24 Sep
Ransomware useUnknown
Named CISA actorNone
OT / process impactNone claimed

What happened

CISA published two 25 September KEV alerts. The JSON freeze we retrieved is catalog 2026.09.25, dateReleased 2026-09-25T18:58:16Z, count 1726 (yesterday’s WSO2 Daily Top froze 2026.09.24 at 1723). The two-CVE alert names SharePoint CVE-2026-65660 and MikroTik RouterOS CVE-2026-67279. A separate one-CVE alert names WordPress Core CVE-2026-87902, which we already assessed on [24 September](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). All three rows are due 28 September. NVD last-modified 26 September 04:17 UTC.

The 65660 KEV row: vendor Microsoft, product SharePoint, CWE-94, ransomware Unknown, forensic triage Yes. Notes point at the MSRC advisory, BOD 26-04, and NVD.

Microsoft’s own advisory is the technical close:

CCCS AL26-023, dated 24 September — one day before the KEV row — is the national-CERT corroboration. It restates CWE-94, authenticated arbitrary code execution, and the chain: with other SharePoint vulnerabilities, pre-authentication RCE is possible on servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates face elevated risk. CCCS also records that SharePoint Enterprise Server 2016 and Server 2019 are end of life as of 15 July 2026. The August patches still exist; the support clock does not.

Fixed builds in CCCS, matching Microsoft’s affected-data ranges on NVD:

ProductClose
SharePoint Enterprise Server 201616.0.5565.1001
SharePoint Server 201916.0.10417.20198
SharePoint Server Subscription Edition16.0.19725.20522

NVD’s CPE block is messier than that table: Subscription Edition has versionEndExcluding 16.0.19725.20522; the 2016 Enterprise and 2019 CPEs are unversioned product matches. Treat the vendor/CCCS build numbers as the patch instruction. Treat extra CPE shape as ASSESSED NVD encoding, not a second Microsoft product list.

SharePoint in Microsoft 365 is not in the affected-product list. Absence from the advisory is not a statement that the service was never vulnerable. It is not claimed here.

The public exploitation telemetry that is not CISA’s unpublished evidence:

RWP is not reproducing markup, deserialization gadget construction, or request bodies.

Why it matters

On-prem SharePoint is still the document and workflow plane for a large share of enterprises that never finished the Microsoft 365 move — including shops whose 2016 and 2019 farms went end-of-life in July and are still serving pages. A low-privileged authenticated RCE on that plane is not “a spoofing ticket from August.”

Two operational lies will show up in tickets this weekend:

  1. “We closed 65660 as Important spoofing in August.” The original MSRC title, the 6.5 vector with I:N/A:N, and the “Exploitation Less Likely” row are still on the page. They describe publication day, not 25 September. CWE-94 was always code injection. The 27 August recast was labelled informational, which is how a lot of patch programs never reopened the ticket. KEV due Monday is the reopen.
  2. “KEV says authorized, so internet-facing anonymous sites are fine.” The KEV short description is correct about the CVE: authorized attacker, code injection, network. The chain CCCS and Viettel describe is a different ticket — anonymous viewing plus a June-patched delivery path plus 65660. Previdian’s 24 September burst used that shape. Inventory anonymous access and the June updates as well as the August build number. SSVC automatable no is CISA-ADP’s statement about the authenticated CVE, not a census that nobody will script the chain.

BOD 26-04’s forensic-triage flag means the ticket is not closed when the build integer ticks. A farm that has been reachable, unpatched, and (for the chain) anonymously viewable through September may already have a layout-directory webshell. The patch does not rewind that. Microsoft’s notes do not say the update removes a foothold already taken.

No public victim count. CISA, Microsoft, CCCS, Previdian, Viettel, and The Hacker News do not name an actor, a ransomware affiliate, or a confirmed customer breach. Previdian’s one-IP honeypot burst is CONFIRMED as sensor telemetry, not a victim list. RWP is not treating ToolShell’s 2025 Chinese-nexus history as attribution for this CVE. Khoa researched both. That is a researcher overlap, not a campaign merge.

This is IT collaboration infrastructure. A compromised SharePoint farm at an industrial company is not confirmed OT compromise and is not process impact.

Who / what is affected

AssetWhat to assumeStatus
SharePoint Enterprise Server 2016 below 16.0.5565.1001In scopeCONFIRMED vendor / CCCS / NVD
SharePoint Server 2019 below 16.0.10417.20198In scopeCONFIRMED vendor / CCCS / NVD
SharePoint Server Subscription Edition below 16.0.19725.20522In scopeCONFIRMED vendor / CCCS / NVD
Same trains at or above those builds, with all offered packages appliedVendor close for this CVECONFIRMED vendor FAQ
SharePoint Server 2016 / 2019 still running after 15 July 2026 EOLIn scope if below the August build; unsupported going forwardCONFIRMED CCCS lifecycle
SharePoint 2013Viettel says the primitive exists; Microsoft does not list it; out of support since April 2023ASSESSED researcher; no vendor patch
SharePoint in Microsoft 365Not in the affected listUNKNOWN / not claimed
Sites allowing anonymous viewing, missing the 9 June delivery fixElevated to a pre-auth chainCONFIRMED as CCCS/Viettel/Previdian description of a separate bug
Named victimsNone publishedUNKNOWN
OT / ICS / processNot claimedNo evidence
CISA ransomware fieldUnknownCONFIRMED catalog

Internet-reachable on-prem farms, Central Administration, and any site with anonymous viewing enabled are the inventory unit. That is configuration, not an exploit recipe.

Technical context

RWP is not reproducing ToolPane markup, Register-directive quote injection, or deserializer payloads.

What the primary records give defenders:

ATT&CK mapping for what is stated:

Follow-on that is not claimed: a named APT, ransomware-Known, confirmed machine-key theft at a named customer, or OT/process impact. Older ToolShell traffic centered on ToolPane.aspx; Previdian notes hunting only that endpoint would miss AddGallery.aspx / designgallery.aspx. That is a detection gap, not a statement that this CVE is ToolShell.

Threat / exploitation status

ClaimStatusBasis
In KEV, added 25 Sep, due 28 Sep, catalog 2026.09.25 count 1726CONFIRMEDCISA two-CVE alert + JSON
Exploitation in the wildCONFIRMED as KEV criterion and as Microsoft 25 Sep statusCISA; MSRC; CISA-ADP SSVC active
CCCS aware of active exploitation, 24 SepCONFIRMED as national CERTAL26-023
Previdian 12-request honeypot burst 24 Sep; webshell path 25 SepCONFIRMED as sensor telemetryPrevidian
CWE-94, CVSS 8.8, PR:L, on-prem 2016/2019/SECONFIRMEDMSRC; NVD
Original August label spoofing / 6.5; 27 Aug recast RCE / 8.8CONFIRMED as vendor revision historyMSRC; THN 22 Sep; NVD
Victim count / actorUNKNOWNNo named set in CISA, Microsoft, CCCS, Previdian
Ransomware useUnknownCatalog field
Forensic triage requiredYesCatalog field
SSVC active / automatable no / totalCONFIRMED as CISA-ADP, 24 Sep stampNVD
Pre-auth chain on anonymous + June-unpatchedCONFIRMED as described by CCCS/Viettel; observed as attempt by PrevidianNot the KEV short description
OT / physical-process impactNot claimedNo evidence

High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 8.8, CWE-94, the three product trains and close builds, forensic-triage flag, ransomware Unknown, Microsoft’s 25 September exploitation sentence, the August spoofing-to-RCE recast, CCCS EOL date, Previdian’s 24 September timestamp and webshell path. Moderate confidence that internet-reachable on-prem farms, especially those still on 2016/2019 after July EOL, are the dominant real-world condition (product role + CCCS guidance; no public census). Low confidence on CISA’s unpublished exploitation evidence, on any victim identity, on whether SharePoint 2013 is practically exploitable in 2026, and on whether the August build displaces a webshell already written.

What defenders should do

  1. Inventory on-prem farms by product train and build, not “we are on Microsoft 365.” Enterprise 2016, 2019, Subscription Edition, internet exposure, anonymous-viewing setting, and whether Central Administration is reachable from untrusted networks. Record exposure for BOD 26-04. 2016 and 2019 past 15 July are still this CVE if below the August build; they are also a migration ticket.
  1. Preserve, then patch, then assume the layout directory was already written. Snapshot IIS/SharePoint ULS, web-application anonymous policy, web-part gallery changes, machine-key access, and %COMMONPROGRAMFILES% / _layouts listings before you roll the August 11 packages. Apply all MSRC-offered packages for the installed product. Confirm the running build is at or above 16.0.5565.1001 / 16.0.10417.20198 / 16.0.19725.20522. CISA’s notes do not say the patch removes a foothold already taken.
  1. Hunt the 24–25 September shape, not only ToolPane.aspx. POST to AddGallery.aspx and designgallery.aspx (including repeated /_layouts/ prefixes) with DisplayMode=Edit. New file /_layouts/15/sphealth.aspx. Unexpected web-part modifications. AMSI/Defender detections on SharePoint worker processes. Assemblies named wt3k3sij.dll or 24e5mo4s.dll — Previdian published SHA-256 d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742 and a151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1. Source IP 169.150.248.21 is this sensor’s burst, not a blocklist of the campaign. CCCS also flags suspicious machine-key access and deserialization/web-shell behaviour.
  1. Close the chain, not only the CVE row. Disable anonymous viewing where it is not a documented business requirement. Confirm the June 2026 SharePoint security updates that Viettel and CCCS treat as the anonymous-delivery close. Enable AMSI integration for SharePoint web applications in Full Mode where operationally feasible (CCCS). Restrict Central Administration.
  1. Do not let the August title drive the scanner severity. If your vuln workflow still keys 65660 as spoofing 6.5, override it to KEV / RCE 8.8 / forensic triage. The original exploitability table is not the 25 September status line.
  1. Sequence the rest of this freeze, then yesterday’s. Same catalog: CVE-2026-87902 (WordPress Core, already [Thursday’s Daily Top](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/), now KEV, forensic triage Yes, due 28 September) and CVE-2026-67279 (MikroTik RouterOS SSH rekey skips authentication, CWE-841, chained to already-KEV CVE-2026-86060, forensic triage No, due 28 September; vendor close 6.49.21 / 7.23.4 / 7.24.2). Due tomorrow: [WSO2 CVE-2026-5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) and Adobe Commerce CVE-2026-71362.

This is not an exploitation guide. Use Microsoft’s security updates table.

RWP assessment

Score 8.9. Same-day vendor confirmation and KEV add, a three-day BOD 26-04 clock with forensic triage, on-prem SharePoint as the enterprise document plane, and an August spoofing label that will leave farms on the wrong ticket. That is the highest-leverage new row in catalog 2026.09.25.

It outranks CVE-2026-87902 (WordPress Core, same freeze, same due date, unauthenticated include, already exploited when we published Thursday) as a daily because the WordPress primitive is not new today — the KEV row is a clock on a story we already shipped. It outranks CVE-2026-67279 (MikroTik RouterOS, same freeze) because 67279 is the missing first half of CERT Polska’s MikroTrick chain; CVE-2026-86060 has been on KEV since 10 September, and we already sequenced that chain on 9 and 11 September. A second RouterOS row is a real federal clock. It is not a first look. It outranks Kiteworks’ 25 September precautionary customer shutdown (federal intelligence, no CVE, vendor says no indication of compromise, current release 9.5.1) because evidence quality for a confirmed vulnerability is poor even though the operational ask — take MFT offline — is unusual. It outranks a second day on [WSO2 5430](/posts/2026-09-25-wso2-cve-2026-5430-kev/) because tomorrow’s due date is not a new technical finding.

The failure mode to sand down is “August said spoofing” and its twin, “authorized, so the anonymous site is fine.” If the running build is below the table and the farm still serves pages, you are in CISA’s denominator. If you only grepped for ToolPane.aspx, you inventoried last year’s path.

What we are watching

Sources

Sources

  1. CISA — Adds two KEV including CVE-2026-65660
  2. CISA — Adds one KEV CVE-2026-87902
  3. CISA — KEV JSON feed catalog 2026.09.25
  4. CISA — Known Exploited Vulnerabilities Catalog
  5. CISA — BOD 26-04
  6. Microsoft — CVE-2026-65660 Security Update Guide
  7. NVD — CVE-2026-65660
  8. CVE — CVE-2026-65660
  9. CCCS — AL26-023 SharePoint CVE-2026-65660
  10. Previdian — Two-stage SharePoint exploitation attempts
  11. The Hacker News — SharePoint spoofing listing enables authenticated RCE
  12. Viettel Cyber Security — SharePoint CVE-2026-65660
  13. BleepingComputer — CISA warns of SharePoint, WSO2, Adobe Commerce flaws
  14. CISA — CVE-2026-67279 KEV row
  15. MikroTik — September 2026 vulnerability
  16. CERT Polska — MikroTrick technical analysis
  17. Kiteworks — Precautionary shutdown advisory