CVE-2026-65660: SharePoint code injection reachable by low-privilege user
A code injection flaw, CVE-2026-65660, has been found in Microsoft SharePoint Server and is exploitable by an authenticated low-privilege user. It was added to the KEV catalog after observed exploitation; Microsoft has released updates.
- CVE-2026-65660 is a code injection in SharePoint Server
- Exploitation needs only a low-privilege account
- Added to KEV catalog after real-world attacks
- Microsoft released patches for affected versions
Read next
Security