A misclassified Microsoft SharePoint vulnerability is now being actively exploited in the wild, with attackers deploying webshell backdoors on unpatched servers — and the federal patching deadline has already come and gone.
What Happened
CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server, has escalated from a quiet patch in August to a full-blown exploitation campaign in less than seven weeks. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 25, giving federal agencies a remediation deadline of September 28 — a deadline that passed yesterday with many organizations still scrambling to apply fixes.
Threat intelligence firm Previdian documented the first exploitation attempts on September 24, just two days after Vietnamese security firm Viettel Security publicly disclosed technical details of the vulnerability. By September 29, Previdian had recorded 19 exploitation attempts from five unique attacker IPs across three countries — the United Kingdom, Israel, and the United States.
The Vulnerability
CVE-2026-65660 is a SafeControls quote-injection flaw that enables remote code execution on affected SharePoint servers. It carries a CVSS score of 8.8 (High), with the attack vector classified as network-based, requiring low privileges, low complexity, and no user interaction — a dangerous combination.
What makes this vulnerability particularly treacherous is its history. When Microsoft first patched it in the August 2026 Patch Tuesday update, the company classified it as a medium-severity spoofing issue with a CVSS score of just 6.5. It was not until August 27 that Microsoft reclassified it as a high-severity remote code execution vulnerability and bumped the score to 8.8. That initial misclassification likely caused many security teams to deprioritize the patch, leaving their environments exposed when exploitation began weeks later.
The flaw affects three versions of SharePoint Server:
- SharePoint Server 2016 (versions before 16.0.5565.1001)
- SharePoint Server 2019 (versions before 16.0.10417.20198)
- SharePoint Server Subscription Edition (versions before 16.0.19725.20522)
Notably, SharePoint Server 2016 and 2019 both reached end of support on July 15, 2026 — just weeks before this vulnerability was patched. Organizations still running these versions face the uncomfortable reality that while security patches were issued, they are now operating on unsupported platforms that will not receive future fixes.
How the Attack Works
Security researchers have pieced together a detailed picture of the exploitation chain. The attack requires an authenticated user with low-level access — a relatively easy bar to clear in most enterprise environments where SharePoint is widely used and many employees hold accounts.
Attackers use a two-stage payload delivery process. The initial payload, roughly 7,800 bytes, deploys an ActivitySurrogateDisableTypeCheck gadget that disables .NET type-checking safeguards. This opens the door for a much larger secondary payload — over 535,000 bytes — that uses an ActivitySurrogate gadget carrying an embedded malicious assembly dubbed “SdLoader.” This loader uses AES decryption routines and .NET’s Assembly.Load() capability to execute arbitrary code on the server.
The observed attack paths target specific SharePoint layouts pages, including /_layouts/15/AddGallery.aspx and /_layouts/15/designgallery.aspx, using query string parameters job=all&DisplayMode=Edit to trigger the vulnerability. The ultimate goal in observed attacks has been deploying a webshell backdoor at /_layouts/15/sphealth.aspx — a filename chosen to blend in with legitimate SharePoint health-monitoring pages.
While the vulnerability requires authentication on its own, researchers warn it can be chained with separate anonymous access weaknesses to achieve unauthenticated remote code execution, raising the threat level even further for internet-facing SharePoint deployments.
Who Is Affected
The impact is broad. SharePoint Server is one of the most widely deployed enterprise collaboration platforms in the world, used by governments, financial institutions, healthcare organizations, and corporations of all sizes. CISA’s KEV catalog now lists 16 SharePoint vulnerabilities in total, with eight discovered and patched in 2026 alone — an indicator of sustained attacker interest in the platform.
Federal agencies operating under CISA’s Binding Operational Directive 26-04 were required to complete remediation by September 28 and perform forensic triage on affected systems. But the mandate does not extend to private-sector organizations, many of which are likely still running vulnerable configurations. The short three-day window between the KEV listing and the remediation deadline was unusually aggressive, reflecting CISA’s assessment of the severity of active exploitation.
Organizations running SharePoint 2016 or 2019 are in an especially difficult position. With those versions now end-of-life, applying the August patch is a stopgap measure at best. Long-term security requires migrating to SharePoint Server Subscription Edition or SharePoint Online, a process that many organizations have been slow to undertake.
Practical Takeaways
Patch immediately. If you have not applied the August 2026 security updates for SharePoint, do so now. The patched build numbers are 16.0.19725.20522 (Subscription Edition), 16.0.10417.20198 (2019), and 16.0.5565.1001 (2016).
Hunt for indicators of compromise. Check your SharePoint servers for the webshell indicator at /_layouts/15/sphealth.aspx. Review IIS logs for suspicious requests to /_layouts/15/AddGallery.aspx and /_layouts/15/designgallery.aspx with the job=all&DisplayMode=Edit query parameters. Look for unusual .NET assembly loading activity.
Do not rely on initial severity ratings. This vulnerability was originally rated 6.5 and classified as a spoofing issue. Security teams that triaged patches based on that initial assessment missed the true risk. When vendors reclassify vulnerabilities, re-evaluate your patching priorities accordingly.
Plan your migration. If you are still on SharePoint 2016 or 2019, the end-of-support clock has already run out. This incident is a clear signal that attackers are actively targeting SharePoint, and running on unsupported versions without a migration plan is an increasingly untenable risk.
Limit internet exposure. SharePoint servers should not be directly accessible from the internet without additional protective controls. Use a reverse proxy, VPN, or zero-trust network access solution to reduce the attack surface, particularly given the potential for chaining this flaw with authentication bypass weaknesses.
This incident is a textbook case of how a seemingly moderate vulnerability can escalate rapidly when technical details go public and attackers move fast. The gap between patch release and exploitation was just six weeks — and the gap between public disclosure and active attacks was measured in days. In the current threat landscape, that timeline is the new normal.
Leave a comment