As cited
Copy frozen at (site build).
vulnerabilities
AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
The Canadian Centre for Cyber Security issued Alert AL26-023 on September 24, 2026, regarding active exploitation of CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code. When chained with other SharePoint vulnerabilities, the flaw can enable pre-authentication remote code execution on servers configured for anonymous access. The Cyber Centre urges organizations to patch affected versions of SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition, and to restrict internet exposure of SharePoint servers while strengthening access controls and monitoring for exploitation activity.
Why it matters: Organizations running on-premises SharePoint Server, particularly those exposed to the internet or running unsupported versions (2016 and 2019 reached end of life July 15, 2026), must apply fixes immediately to prevent authenticated or chained pre-authentication remote code execution attacks already observed in the wild.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
The Canadian Centre for Cyber Security has issued an alert regarding active exploitation of CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code. When chained with other SharePoint vulnerabilities, it can achieve pre-authentication remote code execution on servers configured for anonymous access. Organizations should upgrade to patched versions, restrict internet exposure of SharePoint servers, enforce multifactor authentication for administrators, and monitor for suspicious activity.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face immediate compromise risk if they have not patched to the fixed versions specified; administrators must prioritize this update and implement internet access restrictions to mitigate pre-authentication exploitation chains.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
The Canadian Centre for Cyber Security has issued an alert regarding active exploitation of CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code and, when chained with other vulnerabilities, enables unauthenticated remote code execution on servers configured for anonymous access. The vulnerability affects SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition, with fixed versions available for each. The centre recommends upgrading affected instances, restricting internet exposure, implementing multifactor authentication (MFA) for administrators, enabling antimalware scanning, and monitoring for indicators of compromise including unusual administrative activity and web shell deployment.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face immediate risk of compromise from active exploitation; patching to the specified fixed versions is the primary remediation step today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
The Canadian Centre for Cyber Security has issued an alert regarding active exploitation of CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code and, when chained with other vulnerabilities, enables unauthenticated remote code execution on servers configured for anonymous access. The vulnerability affects SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition, with fixed versions available for each. The centre recommends upgrading affected instances, restricting internet exposure, implementing multifactor authentication (MFA) for administrators, enabling antimalware scanning, and monitoring for indicators of compromise including unusual administrative activity and web shell deployment.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face immediate risk of compromise from active exploitation; patching to the specified fixed versions is the primary remediation step today.
- Source published
- First seen by Cybersecurity Tracker