SharePoint's “Spoofing” Bug Was RCE All Along — and the Federal Patch Deadline Is Today
On Friday 25 September 2026 CISA added CVE-2026-65660, a code-injection flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog — with a federal patch deadline of today, 28 September. The flaw carries a CVSS 8.8 and lets an authenticated, low-privileged attacker execute arbitrary code over the network with no user interaction. It arrived in KEV alongside the MikroTik RouterOS flaw covered in this site's MikroTrick briefing — a weekend double-header of edge-and-core infrastructure under confirmed attack, days after the NetScaler zero-days.
The detail that should change how teams triage vendor labels: Microsoft originally published this flaw on 11 August as a spoofing vulnerability, rated exploitation "less likely." It has since revised the advisory — title now "Remote Code Execution Vulnerability," impact RCE — stating that as of 25 September it held reliable evidence of observed attacks. A bug the spreadsheet said was cosmetic turned out to be code execution with a public exploit path. Severity labels describe the vendor's understanding at a point in time, not the flaw's ceiling.
SafeControls bypass, in-memory webshell, public markup
The technical analysis comes from Viettel Cyber Security researcher Dinh Ho Anh Khoa, who describes the flaw as another bypass of SharePoint's SafeControls protection — the mechanism meant to stop untrusted server-side classes from being instantiated while SharePoint parses page and Web Part markup. The failure sits in the ToolPane component's handling of attacker-controlled Register directives, which map tag prefixes to ASP.NET controls. ToolPane separates the directives from control markup and validates type names, but SharePoint then reconstructs the directives by placing attribute values inside double quotation marks — and embedded quotes are not safely escaped. A malicious value alters the reconstructed directive after the safety check but before ASP.NET parses the control, registering otherwise-dangerous .NET classes. Khoa's demonstrated chain runs through XamlServices.Parse(), an ExpandedWrapper generic type, ObjectDataProvider, and LosFormatter deserialization.
Two properties raise the urgency beyond a standard authenticated-RCE. First, the technique can produce an in-memory webshell rather than writing one to disk — fewer filesystem artifacts, harder incident response, and a reason to examine worker-process behavior, anomalous assemblies, and volatile memory rather than just hunting for dropped files. Second, working exploit markup is public, which collapses the reproduction barrier for every actor watching KEV additions. Previdian telemetry counted 16 exploitation attempts against its sensors on 24 September from IP addresses in the U.K. and Israel. The researcher additionally showed the flaw can combine with a separate ToolPane authentication weakness into pre-authentication RCE where a deployment permits anonymous access to suitable pages — a route Microsoft reportedly closed with its 9 June update, so unpatched-against-June systems are the ones holding the worst-case configuration.
What to do
- Patch to the August builds now — the federal deadline is today. 16.0.5565.1001 for SharePoint 2016, 16.0.10417.20198 for SharePoint 2019, 16.0.19725.20522 for Subscription Edition. Microsoft requires every applicable update package; 2016 administrators may need both listed packages.
- Close the anonymous-access path regardless. Restrict internet and anonymous exposure of SharePoint, and confirm the June update is applied — it shuts the pre-authentication chain even where the August RCE fix is still queued.
- Hunt for markup, not just shells. Audit low-privilege accounts, look for suspicious POSTs carrying unusual Web Part markup or encoded XAML, and review worker processes, unexpected child processes, and loaded assemblies for in-memory implants.
- Preserve before you reboot. Capture IIS, ULS, Windows event, PowerShell, and endpoint telemetry before restarting potentially compromised servers — restarts can destroy the volatile evidence an in-memory technique barely leaves behind.
- SharePoint 2013 shops: treat this as a migration trigger. The underlying technique reportedly affects 2013, which left support in April 2023 — no security update is coming for it. Isolate or migrate; there is no patch to wait for.
Sources:
- CISA — Known Exploited Vulnerabilities catalog (CVE-2026-65660 added 25 September 2026, due 28 September 2026; CWE-94 code injection)
- Microsoft MSRC — CVE-2026-65660 advisory (revised 25 September 2026; “reliable evidence of observed attacks”; affected builds and required packages)
- The Hacker News — “SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild” (26 September 2026; KEV additions, Previdian telemetry, MikroTrick chain)
- Cyber Security News — “Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges” (22 September 2026; Viettel analysis, SafeControls bypass, in-memory webshell, pre-auth chain, build numbers)
- NVD — CVE-2026-65660 (CVSS 8.8, AV:N/AC:L/PR:L/UI:N; SharePoint 2016/2019/Subscription Edition; CISA exploit-added 2026-09-25)