Security Advisory Desk
unratedQCS priority 70/100Microsoft

CVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint has a security flaw that allows an attacker with authorized access to inject malicious code and potentially execute it over the network.

QCS published 6/10/2026, 1:41:24 pm ISTVendor disclosure 25/9/2026, 5:30:00 am ISTVerified 6/10/2026, 1:41:24 pm ISTRevision 1

In plain language

What this advisory means

Microsoft SharePoint has a security flaw that allows an attacker with authorized access to inject malicious code and potentially execute it over the network.

Technical explanation

How the issue affects the environment

This vulnerability in Microsoft SharePoint involves code injection (classified under CWE-94). An attacker with valid authorization can exploit this flaw to run arbitrary code remotely via network communications.

Operational impact

Why teams should care

If exploited, this issue could allow attackers to execute unauthorized code in SharePoint environments, potentially compromising data integrity and service availability. Organizations using SharePoint must prioritize mitigating this risk to safeguard sensitive information and maintain operational continuity.

Immediate action

Apply mitigations as directed by Microsoft according to their official security guidance. Organizations must comply with CISA’s Binding Operational Directive (BOD) 26-04 on prioritizing security updates based on risk and perform forensic triage as outlined by CISA to detect potential compromise. If using cloud services for SharePoint, follow applicable BOD 26-04 recommendations or discontinue using the product if mitigations are unavailable.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • CISA Known Exploited Vulnerabilities catalog entry dated 2026-09-25 confirms code injection vulnerability in SharePoint allowing remote code execution by authorized attackers.
  • CISA advisory mandates mitigation application and forensic triage per BOD 26-04 guidance.
  • Microsoft’s official update guide and National Vulnerability Database provide further details and tracking for this CVE.
  • No CVSS score or affected/fixed version details are provided by official sources.

Authoritative reference

CISA Known Exploited Vulnerabilities

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source