chiprook
← Security
SecuritySeptember 22, 2026, 18:17

SharePoint Flaw Reclassified: Spoofing Bug Enables Authenticated RCE

Viettel Cyber Security researcher Dinh Ho Anh Khoa published full details of CVE-2026-65660, which affects SharePoint Server 2016, 2019 and Subscription Edition. Microsoft initially rated it a spoofing flaw with a CVSS score of 6.5, but it actually enables authenticated remote code execution. Patches have been released.

SharePoint Flaw Reclassified: Spoofing Bug Enables Authenticated RCE
#Microsoft#SharePoint
Read next
Security

D-Link warns of max severity zero-day in DIR-822A routers

Security

Okta launches AI agent runtime gateway, forms Blueprint Alliance with AWS and CrowdStrike

Security

CSC: 90% of firms see AI-driven rise in IP infringement

Security

Over a Third of Industrial Firms Cite Cybersecurity Risk as Top Growth Obstacle