Mastodon Mastodon Mastodon Mastodon

CVE-2026-65660 in SharePoint: spoofing or remote code execution — what is known and what to do

Photo of author

CyberSecureFox Editorial Team

Published:

On 11 August 2026, Microsoft released security updates for SharePoint Server 2016, 2019, and Subscription Edition to fix the vulnerability CVE-2026-65660. Officially, the vulnerability is classified as spoofing with a CVSS score of 6.5 and a Moderate severity rating. However, a researcher from Viettel Cyber Security claims that the vulnerability allows authenticated remote code execution. This classification discrepancy creates a risk that security teams relying on official ratings may underestimate the threat when prioritizing patches. The updates are already available, and SharePoint administrators should apply them without delay.

Technical details and classification discrepancy

According to the entry in the GitHub Advisory Database, which refers to NVD and Microsoft’s security bulletin, CVE-2026-65660 is described as a spoofing vulnerability that allows an authenticated attacker to perform spoofing over the network. The severity level is Moderate, with a CVSS score of 6.5. At the same time, both entries — the official bulletin and the CVE record — reference CWE-94 (Improper Control of Generation of Code, i.e., code injection), which is atypical for a pure spoofing vulnerability.

According to the original report, a separate CVE record updated on 11 September describes the same vulnerability as remote code execution with an NVD score of 8.8. However, at the time of verification, the available registry entry still listed the classification as “spoofing” with a score of 6.5. This discrepancy could not be independently resolved — the direct MSRC page for CVE-2026-65660 turned out to be unavailable for automated data retrieval.

The affected versions confirmed by Microsoft’s update pages are:

The original report also mentions SharePoint 2013 as a potentially vulnerable version, but Microsoft did not include it in the list of affected products. SharePoint 2013 has not received security updates since April 2023.

Why the classification matters

Microsoft’s update pages for each of the three SharePoint versions list CVE-2026-65660 as part of a package that fixes vulnerabilities in several categories — including spoofing and remote code execution. However, these pages do not specify which impact category applies to each particular CVE identifier. Thus, the update pages confirm the existence of a patch but do not resolve the dispute over the actual impact of CVE-2026-65660.

The assignment of CWE-94 to both entries — the spoofing one and the purported RCE one — is noteworthy. Code injection as a vulnerability class implies the ability to execute arbitrary code, which does not align well with a “spoofing” classification that has no effect on integrity and availability.

For security teams that use automated CVSS-based prioritization, the difference between 6.5 (Moderate) and 8.8 (High) can determine whether a vulnerability is included in the next patch cycle or postponed.

Exploitation status

CVE-2026-65660 is not listed in the CISA Known Exploited Vulnerabilities catalog. According to the original report, there have been no observed real-world attacks exploiting it, and Microsoft rates the likelihood of exploitation as low. However, the report points to the existence of public exploit code, which increases the probability of attacks emerging in the foreseeable future.

It is worth noting the context: a related vulnerability, CVE-2026-55040 — an authentication bypass in SharePoint discovered by the same researcher — was added to the CISA KEV catalog on 18 August 2026 with a remediation deadline of 21 August. According to the original report, exploitation of CVE-2026-55040 began shortly after the publication of the details. We have already written about this vulnerability — the history of CVE-2026-55040 shows that SharePoint vulnerabilities from this researcher quickly attract attackers’ attention.

Recommendations

Regardless of which classification ultimately proves correct, the required actions for administrators are the same:

  • Install the 11 August 2026 updates for SharePoint Server 2016 (KB5002905), 2019 (KB5002894), and Subscription Edition (KB5002893). The updates are available via Microsoft Update and the Download Center.
  • Review your anonymous access configuration for SharePoint pages. The original report notes that if anonymous access is allowed, the vulnerability can be combined with another (already fixed) authentication bypass to enable attacks without prior authentication. Make sure the June updates are also installed.
  • Organizations using SharePoint 2013 should keep in mind that this version no longer receives security updates. The researcher’s claim that it is vulnerable has neither been confirmed nor refuted by Microsoft. Migration to a supported version remains the only reliable solution.
  • Do not rely solely on the CVSS 6.5 rating when prioritizing. The assignment of CWE-94, the presence of public exploit code, and the history of rapid exploitation of SharePoint vulnerabilities from the same researcher are all factors that justify a higher priority.

SharePoint Server administrators should treat CVE-2026-65660 as a high-priority vulnerability and install the August updates without waiting for the classification dispute to be resolved. With public exploit details available and a working patch in place, delaying remediation is unjustified — in this case, the difference between “spoofing” and “remote code execution” is less important than the fact that both a fix and attack code exist.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.