CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660, to its KEV Catalog after evidence showed the flaw was being exploited in attacks.

The vulnerability affects Microsoft SharePoint and could enable an authorized attacker to execute code remotely over a network, creating a significant risk for organizations that rely on SharePoint for document management, collaboration, and internal business workflows.

CVE-2026-65660 is classified as CWE-94, or Improper Control of Generation of Code, commonly referred to as code injection. This weakness arises when an application processes externally influenced input as executable code without sufficient validation or controls.

In a SharePoint environment, successful exploitation could allow an attacker who already has authorized access to run attacker-controlled code, potentially providing a path to manipulate data, deploy malicious tools, establish persistence, or move deeper into an enterprise network.

According to the catalog update published by CISA, CISA added the Microsoft SharePoint vulnerability to its KEV Catalog on September 25, 2026, with a remediation due date of September 28, 2026.

The short remediation window reflects the urgency attached to vulnerabilities known to be actively exploited. While CISA has not identified whether CVE-2026-65660 has been used in ransomware campaigns, the agency requires forensic triage under Binding Operational Directive 26-04, indicating that affected organizations should not treat patching as the only required response.

The advisory is especially relevant to federal civilian executive branch agencies, which must follow CISA’s Binding Operational Directive requirements.

However, the warning should also prompt private-sector organizations to prioritize their own SharePoint environments.

SharePoint servers can contain sensitive internal documents, business records, project data, credentials, and integrations with identity systems, making them valuable targets for attackers seeking access to enterprise environments.

Microsoft describes CVE-2026-65660 as a code injection issue that may allow an authorized attacker to execute code over a network. The “authorized attacker” condition means exploitation may require valid credentials or an existing authenticated session, but that should not reduce the perceived severity.

Threat actors frequently obtain legitimate user access through phishing, password reuse, token theft, compromised third-party accounts, or abuse of weakly protected service accounts. Once inside, a SharePoint code execution flaw can turn limited access into broader operational control.

CISA instructed organizations to apply mitigations according to Microsoft’s vendor guidance and to follow BOD 26-04 requirements for prioritizing security updates based on risk.

Agencies and defenders must also evaluate whether affected SharePoint assets are exposed to the internet and follow applicable guidance for cloud services. Where mitigations are unavailable, CISA advises discontinuing use of the affected product.

Forensic triage is another critical part of the response. Security teams should review SharePoint and Windows event logs, investigate unusual authenticated activity, check for newly created or modified SharePoint components, and hunt for unexpected web shell behavior, suspicious child processes, or anomalous outbound network connections from SharePoint servers.

Identity logs should also be reviewed for unusual sign-ins, token use, privilege changes, and access originating from unfamiliar locations or devices.

Organizations should immediately identify all on-premises and managed SharePoint deployments, confirm the installed version, and apply Microsoft’s available security updates or mitigations.

Teams should also restrict unnecessary internet exposure, enforce multifactor authentication for administrative and user access, apply least-privilege permissions, and closely monitor privileged accounts.

Given CISA’s active-exploitation designation, defenders should assume that unpatched SharePoint instances may be targeted and validate both remediation and signs of prior compromise.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.