AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Number: AL26-023Date: September 24, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint ServerFootnote 1. In response to the Microsoft security advisory, released on August 11, 2026Footnote 2, the Cyber Centre issued AV26-804 Update 3Footnote 3 on September 24, 2026. Tracked as CVE-2026-65660Footnote 4, this vulnerability is an Improper Control of Generation of Code ('Code Injection') (CWE-94)Footnote 5 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers. Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre...

This version

Version
1 of 1
Recorded
September 24, 2026 18:00
Change
Initial
Content hash
21b5cdd17eedc1a366dda702521b5df9
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.