CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVSS
- 8.8
- EPSS
- —
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
Canadian Centre for Cyber Security
AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
Number: AL26-023 Date: September 24, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to…
What we observed
No signals recorded