Home / Sep 28, 2026 / Story
0
#3 SecurityWeek general September 27, 2026 at 09:23 UTC

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

By Eduard Kovacs

AI Summary

CISA added CVE-2026-65660, a Microsoft SharePoint vulnerability, to its Known Exploited Vulnerabilities catalog with a federal agency patching deadline of September 28, confirming active exploitation in the wild. SharePoint servers are a recurring target for initial access due to their internet-facing deployment and integration with corporate identity systems. Federal agencies and enterprises running SharePoint on-premises must treat this as an emergency patch given the KEV listing and imminent deadline.

Relevance score: 82.0/100

# More from September 28