Microsoft SharePoint Server Remote Code Execution Vulnerability
Release Date: 26th September 2026 (Added 6th October 2026)
Impact : HIGH
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-65660 is a code injection vulnerability in Microsoft SharePoint Server that allows an authenticated attacker with low-level access to execute code on the server. Microsoft first published it as a spoofing flaw (CVSS 6.5) and reclassified it as remote code execution on 27 August 2026; the National Vulnerability Database scores it 8.8 (High).
Researchers have shown it can be chained with a separate, already-patched authentication bypass to achieve pre-authentication code execution on servers that allow anonymous page access.
What are the systems affected?
The following on-premises SharePoint products are affected until the August 2026 updates are installed:
Microsoft SharePoint Server 2016 – (Affected)
Microsoft SharePoint Server 2019 – (Affected)
Microsoft SharePoint Server Subscription Edition – (Affected)
Microsoft SharePoint Server 2013 – (Affected; out of support since April 2023, will not receive a fix)
Not affected / patched versions:
SharePoint Server 2016: KB5002905 and KB5002906 (build 16.0.5565.1001 or later)
SharePoint Server 2019: KB5002894 and KB5002896 (build 16.0.10417.20198 or later)
SharePoint Server Subscription Edition: KB5002893 (build 16.0.19725.20522 or later)
What does this mean?
Successful exploitation may allow attackers to:
- Execute arbitrary code on the SharePoint server from a low-privileged authenticated account
- Where chained with an authentication bypass, execute code without any credentials
- Install web shells and persistence, then access SharePoint content and move into the connected internal network
Mitigation process?
CERTVU recommends the following:
-
Apply the August 2026 Security Updates
Install the update for your SharePoint version listed above on every server in the farm, then complete the post-installation configuration steps from the Microsoft update notes. -
Migrate Off SharePoint 2013
Version 2013 will not be patched; retire it or replace it with a supported version. -
Enable AMSI and Reduce Exposure
-
Strengthen Administrative Access
-
Hunt for Compromise
Reference
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-65660
- Download advisory (English): Microsoft SharePoint Server Remote Code Execution Vulnerability