27 SEP 2026 — If you run SharePoint Server on your own hardware, check its patch level. Microsoft confirmed on 25 September that CVE-2026-65660, a flaw it first published in August as a medium-severity spoofing bug, is now being exploited.
The fix is the 11 August update, and servers that installed it are covered. The United States cybersecurity agency has given federal agencies until Monday 28 September to act.
What changed between August and now
CVE-2026-65660 shipped in Microsoft's August Patch Tuesday release. According to reporting by The Hacker News, it was first listed as a spoofing issue scored 6.5, with no impact on integrity or availability.
The Microsoft advisory records two later revisions. On 27 August it changed the impact and title, and the entry now describes a remote code execution vulnerability scored 8.8. On 25 September it added a sentence noting that, as of that date, Microsoft had reliable evidence of observed attacks.
The advisory's separate "exploited" field still read "No" when we checked it on 27 September. CISA acted on the revision note, which is the more recent statement.
Who is exposed
The bug is in on-premises SharePoint Server 2016, 2019 and Subscription Edition. SharePoint Online is not listed. SharePoint 2013 is affected as well, SecurityWeek reports, and will not be fixed because it has been out of support since April 2023.
On paper the attacker needs an account, even a low-privileged one. The technical write-up that made the flaw widely understood came from Dinh Ho Anh Khoa of Viettel Cyber Security, the Vietnamese security company, and SecurityWeek links the attacks that followed to that disclosure.
Why the login requirement matters less
The security company Previdian saw the first attempts against one of its decoy SharePoint servers at about 12:00 UTC on 24 September. The requests carried no login cookie and no authorisation header.
Previdian reads the attempts as pairing this August bug with an older SharePoint weakness that Microsoft fixed on 9 June. That earlier issue let a request reach the vulnerable component without signing in, but only on sites configured to allow anonymous viewing. Previdian says it does not know the CVE number Microsoft gave the June issue.
In practice, a server that missed both the June and August updates, and lets anonymous visitors view a site, can be attacked with no account at all. A server that took either update breaks that chain.
Previdian's 25 September update reports a web shell, a backdoor page, planted at /_layouts/15/sphealth.aspx. Its decoy does not show whether the final payload ran, and nobody has published a count of compromised organisations.
The catalogue keeps growing
CISA's 25 September alert added this flaw and one in MikroTik RouterOS. Our count of the catalogue's 25 September edition finds 16 SharePoint entries since November 2021. Eight arrived in 2026: one each in March and April, four in July, one on 18 August and this one.
When we counted four SharePoint additions in 22 days in July, the total stood at 14. Two more have followed in the nine weeks since.
You can run Microsoft's published vector, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, through our CVSS 3.1 base score calculator to see how a network-reachable flaw needing only a low-privileged account reaches 8.8.
What to check on a server
Start with the patch level. A server with the August 2026 update is fixed against this bug, and one with the June update is closed to the anonymous route.
Previdian's advice is to check whether any site allows anonymous viewing and whether it needs to. It also suggests searching web logs for unauthenticated POST requests to AddGallery.aspx or designgallery.aspx carrying DisplayMode=Edit, and looking for the sphealth.aspx file.
CISA's catalogue entry marks this flaw for forensic triage, so federal agencies are expected to look for signs of compromise, not just patch. Any organisation that left an on-premises server without the August update into late September has the same reason to look.
For SharePoint 2013, no patch is coming. The choices are to isolate the server or replace it.