← All CVEs NewScan detects
criticalKEV

CVE-2026-65660

SharePoint Server code injection - an authenticated caller executes code on the server over the network (CVSS 8.8), actively exploited September 2026

Severity
critical
Affected product
Microsoft SharePoint Server
Affected versions
Microsoft SharePoint Server all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
1% chance of exploitation in the next 30 days
Added to NewScan
2026-09-26
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Microsoft SharePoint Server appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-26 (/daily-cve) from CISA KEV. NVD: 'improper control of generation of code (code injection) in Microsoft Office SharePoint allows an authorized attacker to execute code over a network'; thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html reports it exploited in the wild alongside the MikroTik RouterOS chain. ADVISORY ONLY, and deliberately: 'authorized attacker' means the code path is behind a login, so there is no anonymous request that demonstrates it and a probe would have to authenticate as a real user of the customer's SharePoint to try - which this scanner does not do. The version gate is the same dead end as the four rows above and for the same reason, re-checked rather than assumed: MicrosoftSharePointTeamServices publishes a build number, Microsoft ships the fix as a per-version cumulative update whose build differs across Subscription Edition / 2019 / 2016, and NVD's CPE set carries no version bound at all - so any `lt` here would be invented. What this row IS worth: SharePoint on-prem is already fingerprinted (appliances.json, the header above), so the row attaches a KEV-listed, actively-exploited critical to every SharePoint the scanner finds and tells the operator to confirm their September 2026 patch level - which is the honest form of the claim. The chained JWT bypass CVE-2026-55040 above is the anonymous arm we CAN prove, and test_jwt_forgery still supplies it.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →