AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660

Imported from official source

Cybersecurity Classified by Officially

Number: AL26-023
Date: September 24, 2026

This Alert is intended for IT professionals and managers.

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint ServerFootnote 1. In response to the Microsoft security advisory, released on August 11, 2026Footnote 2, the Cyber Centre issued AV26-804 Update 3Footnote 3 on September 24, 2026.

Tracked as CVE-2026-65660Footnote 4, this vulnerability is an Improper Control of Generation of Code ('Code Injection') (CWE-94)Footnote 5 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers.

Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre-authentication remote code execution on SharePoint servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates may therefore face an elevated risk of compromise.

The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version:

Important note: Microsoft SharePoint Enterprise Server 2016Footnote 6 and Server 2019Footnote 7 are end of life as of July 15, 2026. Organizations are urged to migrate to a supported version.

The Cyber Centre also recommends organizations to:

  • Identify all on-premises SharePoint Server instances, particularly those exposed to the Internet, and ensure they are running supported versions of Microsoft SharePoint Server.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660

    Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Canadian Centre for Cyber Security — imported from official source
    Official source
    https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
    Imported
    September 24, 2026 18:00
    Versions
    1 recorded
    Identity
    https://cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sha...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.