SharePoint Code Injection Exploited Vulnerability - 20261001001¶
Overview¶
Microsoft has released a security advisory relating to a high-severity vulnerability in SharePoint Server where an authenticated attacker with low-level access to an affected server could send a specially crafted request to execute code on the server via a code injection exploit. User interaction is not required.
Patches addressing the vulnerability have been released and Microsoft is encouraging all affected users to apply the patches.
What is vulnerable?¶
| Product(s) Affected | Version(s) | CVE | CVSS | Severity |
|---|---|---|---|---|
| Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition | from 16.0.0 before 16.0.5565.1001from 16.0.0 before 16.0.10417.20198from 16.0.0 before 16.0.19725.20522 | CVE-2026-65660 | 8.8 | High |
What has been observed?¶
CISA has added one or more of the mentioned items to their Known Exploited Vulnerabilities catalog. The WA SOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.
Recommendation¶
The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):