SharePoint Flaw Reclassified: Spoofing Bug Enables Authenticated RCE
Viettel Cyber Security researcher Dinh Ho Anh Khoa published full details of CVE-2026-65660, which affects SharePoint Server 2016, 2019 and Subscription Edition. Microsoft initially rated it a spoofing flaw with a CVSS score of 6.5, but it actually enables authenticated remote code execution. Patches have been released.
- CVE-2026-65660 affects SharePoint Server 2016, 2019 and Subscription Edition
- Microsoft initially rated it 6.5 on CVSS as a spoofing flaw
- It actually enables authenticated remote code execution
- Patches for the vulnerability have been released
Read next
Security