Microsoft SharePoint Server Remote Code Execution Vulnerability

Release Date: 26th September 2026 (Added 6th October 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-65660 is a code injection vulnerability in Microsoft SharePoint Server that allows an authenticated attacker with low-level access to execute code on the server. Microsoft first published it as a spoofing flaw (CVSS 6.5) and reclassified it as remote code execution on 27 August 2026; the National Vulnerability Database scores it 8.8 (High).

Researchers have shown it can be chained with a separate, already-patched authentication bypass to achieve pre-authentication code execution on servers that allow anonymous page access.

Reference

  1. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-65660