Skip to finding
important · SharePoint — RCE

Attackers are composing anonymous SharePoint delivery with CVE-2026-65660 to install a server-side web shell.

Affects

Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.

On an anonymously viewable on-premises site missing the separate June delivery fix, a WebPartPage route reaches ToolPane processing without authentication. Quote injection then bypasses SafeControls validation and enters attacker-controlled .NET deserialization.

Detail and 3 sources

Observed payloads disable a deserialization safeguard, load an embedded assembly, and create /_layouts/15/sphealth.aspx as a persistent web shell.

Move to a listed fixed build and verify that the separate June anonymous-delivery correction is also present before permitting anonymous access.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 28, 2026