CVE-2026-65660: SharePoint flaw leaves no file on disk
Microsoft patched CVE-2026-65660, rated 8.8, on 11 August 2026 across SharePoint Server 2016, 2019 and Subscription Edition. A low-privileged attacker can execute code via a POST to a WebPartPage, with the payload existing only as an in-memory object and leaving no file behind. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 25 September.
- Flaw rated 8.8, fixes released on 11 August 2026
- Fixed builds: 16.0.5565.1001, 16.0.10417.20198, 16.0.19725.20522
- QiAnXin counted 67,103 at-risk assets and 7,912 addresses worldwide
- CISA added the CVE to its exploited catalog on 25 September with a 28 September deadline
Read next
Security