chiprook
← Security
SecurityOctober 2, 2026, 06:40

CVE-2026-65660: SharePoint flaw leaves no file on disk

Microsoft patched CVE-2026-65660, rated 8.8, on 11 August 2026 across SharePoint Server 2016, 2019 and Subscription Edition. A low-privileged attacker can execute code via a POST to a WebPartPage, with the payload existing only as an in-memory object and leaving no file behind. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 25 September.

CVE-2026-65660: SharePoint flaw leaves no file on disk
#Microsoft#SharePoint#CISA
Read next
Security

CVE-2026-65660: Two-Stage SharePoint Attacks Attempt Web Shell Deployment

Security

CVE-2026-85706: unauthenticated file read in GitLab exploited

Security

F5 BIG-IP APM CVE-2026-94127: unauthenticated RCE that hardening won't stop

Security

CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE