AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
Imported from official source
Number: AL26-023Date: September 24, 2026 This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint ServerFootnote 1. In response to the Microsoft security advisory, released on August 11, 2026Footnote 2, the Cyber Centre issued AV26-804 Update 3Footnote 3 on September 24, 2026. Tracked as CVE-2026-65660Footnote 4, this vulnerability is an Improper Control of Generation of Code ('Code Injection') (CWE-94)Footnote 5 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers. Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre...
This version
- Version
- 1 of 1
- Recorded
- September 24, 2026 18:00
- Change
- Initial
- Content hash
21b5cdd17eedc1a366dda702521b5df9- All versions
- Revision history