Decoding the world of cybersecurity

SharePoint flaw moves into active exploitation

Canada’s Cyber Centre has warned that attackers are exploiting CVE-2026-65660, a SharePoint code-injection flaw Microsoft patched in August.

SharePoint flaw moves into active exploitation
Summary
  • Canada's Cyber Centre said on 24 September that it was aware of active exploitation of CVE-2026-65660.
  • The flaw allows an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers.
  • SharePoint Server 2016 and 2019 reached end of support in July, adding lifecycle risk to organisations still operating those versions.

A Microsoft SharePoint vulnerability patched in August has moved into active exploitation, according to Canada’s national cyber authority, changing an existing patching issue into a potential compromise-assessment problem.

The Canadian Centre for Cyber Security said on 24 September that it was aware of active exploitation of CVE-2026-65660, a code-injection vulnerability affecting multiple versions of Microsoft SharePoint Server.

Microsoft released its security advisory and fixes on 11 August. CVE-2026-65660 can allow an authenticated attacker to execute arbitrary code on a vulnerable SharePoint server over a network.

The change in exploitation status is the new development. Earlier public analysis of the vulnerability had noted no known in-the-wild exploitation, but Canada’s subsequent alert says exploitation is now occurring.

That distinction alters the operational response. A vulnerability assessed as technically serious but not exploited can be handled primarily through patch prioritisation. Once exploitation is confirmed, organisations that operated exposed vulnerable systems also need to consider whether compromise occurred before remediation.

SharePoint is particularly sensitive because on-premises deployments can hold business documents, workflow information, user data, and integrations with other enterprise systems. A server compromise can therefore become a route to information theft, credential access, or further movement rather than remaining an isolated web-application problem.

The Canadian Cyber Centre recommends identifying on-premises SharePoint instances and applying current Microsoft security updates. The organisation has also pointed users towards Microsoft’s vulnerability guidance and its own earlier SharePoint advisory material.

The lifecycle position of older SharePoint installations adds another issue. SharePoint Server 2016 and SharePoint Server 2019 reached the end of support on 14 July 2026, leaving organisations still dependent on those editions with an additional migration and assurance problem.

Unsupported enterprise systems often persist because they are tied to bespoke applications, internal workflows, integration dependencies, or migration programmes that take longer than the vendor lifecycle itself. That can create a widening gap between the business value of keeping a platform operational and the security assurance available for it.

SharePoint has also attracted repeated security attention during 2026, making it important to distinguish individual vulnerabilities rather than treating every advisory as the same incident.

CVE-2026-65660 was already known and patched before the Canadian alert. The fresh development is evidence that attackers are now using the vulnerability.

That makes historical exposure more important. Installing the current fix prevents exploitation of the known flaw, but does not by itself establish whether an attacker reached a vulnerable system earlier.

For organisations still running on-premises collaboration infrastructure, those questions combine vulnerability management with lifecycle risk. Systems can remain deeply embedded in business processes after the preferred support window has ended, leaving migration programmes to compete with operational dependencies while attackers continue to target the installed base.

The Canadian warning therefore turns CVE-2026-65660 from another item in an August patch cycle into a live question about which SharePoint systems were exposed, when they were patched, and whether those systems can still be treated as uncompromised.

×