CVE-2026-65660: Two-Stage SharePoint Attacks Attempt Web Shell Deployment
Previdian observed attacks on SharePoint Server 2016, 2019 and Subscription Edition that chain CVE-2026-65660 with an anonymous access flaw to deliver a XAML deserialization payload and create the sphealth.aspx web shell. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 25.
- Stage 1 payload ActivitySurrogateDisableTypeCheck is 7,834 bytes
- Stage 2 encrypted DLL SdLoader is 535,404 bytes
- Patches: 16.0.5565.1001 for 2016, 16.0.10417.20198 for 2019, 16.0.19725.20522 for SE
- CISA added CVE-2026-65660 to KEV on September 25
Read next
Security