Attackers are composing anonymous SharePoint delivery with CVE-2026-65660 to install a server-side web shell.
Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.
On an anonymously viewable on-premises site missing the separate June delivery fix, a WebPartPage route reaches ToolPane processing without authentication. Quote injection then bypasses SafeControls validation and enters attacker-controlled .NET deserialization.
Detail and 3 sources
Observed payloads disable a deserialization safeguard, load an embedded assembly, and create /_layouts/15/sphealth.aspx as a persistent web shell.
Move to a listed fixed build and verify that the separate June anonymous-delivery correction is also present before permitting anonymous access.