chiprook
← Security
SecuritySeptember 28, 2026, 18:22

CVE-2026-65660: Two-Stage SharePoint Attacks Attempt Web Shell Deployment

Previdian observed attacks on SharePoint Server 2016, 2019 and Subscription Edition that chain CVE-2026-65660 with an anonymous access flaw to deliver a XAML deserialization payload and create the sphealth.aspx web shell. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 25.

CVE-2026-65660: Two-Stage SharePoint Attacks Attempt Web Shell Deployment
#Microsoft#SharePoint#CISA
Read next
Security

CISA adds Microsoft SharePoint and MikroTik RouterOS flaws to KEV catalog

Security

SharePoint Flaw Reclassified: Spoofing Bug Enables Authenticated RCE

Security

Fake passkey setup requests lead to Microsoft 365 compromises

Security

A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs