CVE-2026-65660
SharePoint Server code injection - an authenticated caller executes code on the server over the network (CVSS 8.8), actively exploited September 2026
- Severity
- critical
- Affected product
- Microsoft SharePoint Server
- Affected versions
- Microsoft SharePoint Server all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-26
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Microsoft SharePoint Server appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-26 (/daily-cve) from CISA KEV. NVD: 'improper control of generation of code (code injection) in Microsoft Office SharePoint allows an authorized attacker to execute code over a network'; thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html reports it exploited in the wild alongside the MikroTik RouterOS chain. ADVISORY ONLY, and deliberately: 'authorized attacker' means the code path is behind a login, so there is no anonymous request that demonstrates it and a probe would have to authenticate as a real user of the customer's SharePoint to try - which this scanner does not do. The version gate is the same dead end as the four rows above and for the same reason, re-checked rather than assumed: MicrosoftSharePointTeamServices publishes a build number, Microsoft ships the fix as a per-version cumulative update whose build differs across Subscription Edition / 2019 / 2016, and NVD's CPE set carries no version bound at all - so any `lt` here would be invented. What this row IS worth: SharePoint on-prem is already fingerprinted (appliances.json, the header above), so the row attaches a KEV-listed, actively-exploited critical to every SharePoint the scanner finds and tells the operator to confirm their September 2026 patch level - which is the honest form of the claim. The chained JWT bypass CVE-2026-55040 above is the anonymous arm we CAN prove, and test_jwt_forgery still supplies it.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →