Threat Landscape

SharePoint CVE-2026-65660 — authenticated RCE now ITW; CISA KEV; FCEB clock ends Sep 28.

CVE-2026-65660 is a Microsoft SharePoint code-injection / remote code execution flaw for an authenticated attacker with low privileges (no user interaction). Patched in August 2026 Patch Tuesday. Microsoft’s advisory update: “As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.” CISA added it to KEV on September 25; FCEB BOD 26-04 deadline September 28. Same KEV notice: MikroTik RouterOS CVE-2026-67279 (“MikroTrick” chain). Actor and successful-compromise census: Undisclosed.

Sep 28, 2026 · 3 min read

Authenticated SharePoint RCE, vendor-confirmed observed attacks, federal clock ending today. That is the Monday KEV follow-on — not a second breaking Citrix lead.

Primary: MSRC advisory for CVE-2026-65660 (Microsoft Office SharePoint). Classed as code injection enabling an authorized attacker to execute code over a network. CVSS cited in secondary coverage: 8.8. Microsoft initially framed it as medium-severity spoofing (per Viettel / SecurityWeek); later revised to high-severity RCE. On its own it is a type-check bypass that yields code execution for an authenticated attacker; reaching unauthenticated RCE requires chaining a separate auth-bypass; Microsoft has not published such a chain.

Exploitation timeline (secondary, consistent across SecurityWeek / The Hacker News): roughly six weeks after the August patch, and days after Viettel Security (who reported the bug to Microsoft) published technical details. Previdian (formerly KEVIntel) reported exploitation attempts on September 24; on September 25 it saw attempts to create a webshell backdoor. THN citing Previdian: 16 exploitation attempts against its sensors on Sep 24 (UK / Israel-sourced IPs in that write-up) — that is a sensor attempt count, not a victim census. Who is behind it, how many orgs were hit, and what attackers did post-access beyond webshell attempts: Undisclosed by Microsoft.

CISA Sep 25 alert: two new KEV rows — CVE-2026-65660 (Microsoft SharePoint Code Injection) and CVE-2026-67279 (MikroTik RouterOS Improper Enforcement of Behavioral Workflow). BOD 26-04 still governs FCEB remediation of KEV entries on publicly exposed assets that grant total control post-exploitation; secondary reporting puts the SharePoint federal deadline at September 28.

Optional same-day pair — MikroTrick: CERT Polska technical analysis explains CVE-2026-67279 (SSH rekey state machine lets an unauthenticated client open a session channel) chained with CVE-2026-86060 (argument injection in RouterOS login → attacker-controlled policy mask) for full unauthenticated admin on internet-exposed susceptible RouterOS. CISA had already KEV’d 86060 earlier (Sep 11 per THN); 67279 joined on Sep 25. Primary for the chain: CERT Polska. This brief covers the patch and advisory only, not exploit steps.

POV: If you still run on-prem SharePoint that missed August’s build, today is the FCEB clock and the board clock. Hunt for webshells before you overwrite evidence. Pair MikroTik internet-exposed RouterOS with CERT Polska’s MikroTrick guidance. Sources: MSRC + CISA Sep 25; the Sep 24–25 attempt / webshell window is per SecurityWeek / THN / Previdian. Victim and actor counts stay Undisclosed.

Sources