important · Edge — SharePoint
Attackers are exploiting a SharePoint SafeControls bypass that turns a low-privilege account into server-side code execution.
Affects
Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.
CISA marked the vulnerability as actively exploited on September 25, and Microsoft has published fixes for supported affected versions.
Detail and 5 sources
Sources
ResearchDescription of the security update for SharePoint Server 2016: August 11, 2026 (KB5002905) | Microsoft SupportResearchSecurity Update Guide - Microsoft Security Response CenterResearchSharePointの脆弱性CVE-2026-65660は認証済み攻撃者によるコード実行が可能 — Microsoftの「なりすまし」分類と評価に差、Viettel研究者が技術詳細を公開 | NEXSIGHT CYBER WIREResearchCVE-2026-65660 - Vulnerability Details - OpenCVEVendorCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks