Rewterz

WordPress Click2Shell Flaw Enables RCE via Malicious Link

September 21, 2026
Rewterz

GitLab Email Flaw Enables Code Injection

September 23, 2026

Microsoft SharePoint Flaw Enables Remote Code Execution

Severity

High

Analysis Summary

Microsoft has confirmed a high-severity remote code execution vulnerability, tracked as CVE-2026-65660 with a CVSS score of high, affecting SharePoint Server 2016, 2019, and Subscription Edition. The vulnerability allows an authenticated, low-privileged attacker to execute arbitrary code remotely without user interaction. Successful exploitation could provide access to sensitive SharePoint data and enable credential theft, lateral movement, data exfiltration, and persistent access because SharePoint servers commonly operate with privileged service identities. The flaw was discovered by and involves another bypass of SharePoint’s SafeControls security mechanism.

The vulnerability originates in the ToolPane component, which processes attacker-controlled ASP.NET Register directives used to map tag prefixes to server-side controls. ToolPane validates the directive type names and subsequently reconstructs the directives by placing attribute values inside quotation marks. Because embedded quotation marks are not properly escaped, an attacker can manipulate the reconstructed directive after the security validation has occurred but before ASP.NET parses it. This ordering flaw can allow otherwise restricted .NET classes to be registered and abused through a code-execution chain involving XamlServices.Parse(), ExpandedWrapper, ObjectDataProvider, and LosFormatter deserialization. The publicly available research includes working exploit markup and demonstrates an in-memory webshell technique, potentially leaving fewer filesystem artifacts and making traditional incident-response methods less effective.

Although Microsoft states that exploitation requires authentication and low-level privileges, the researcher demonstrated that CVE-2026-65660 could previously be combined with a separate ToolPane authentication weakness to achieve pre-authentication RCE when anonymous access to suitable SharePoint pages was permitted. Microsoft reportedly addressed that authentication route in its June 9, 2026 update. Microsoft released fixes for CVE-2026-65660 on August 11, 2026, with patched build levels of 16.0.5565.1001 for SharePoint 2016, 16.0.10417.20198 for SharePoint 2019, and 16.0.19725.20522 for Subscription Edition; administrators must install all applicable update packages, and SharePoint 2016 may require both listed packages. The underlying technique was also reported to affect SharePoint 2013, which reached end of support in April 2023, although Microsoft’s official affected-product list covers supported releases.

Microsoft initially assessed CVE-2026-65660 as not publicly disclosed or exploited and considered exploitation less likely; however, the availability of detailed technical research and working exploit material increases the practical risk of exploitation. Organizations should prioritize applying the relevant Microsoft updates, restrict unnecessary internet-facing and anonymous SharePoint access, and review low-privileged accounts. Security teams should hunt for suspicious POST requests containing unusual Web Part markup or encoded XAML, unexpected worker-process behavior, anomalous child processes or assemblies, and other indicators of code execution. During investigations, teams should preserve IIS, SharePoint ULS, Windows Event, PowerShell, and endpoint telemetry before restarting potentially compromised servers, while also considering volatile-memory analysis because an in-memory webshell may not leave a conventional webshell file on disk.

Impact

  • Code Execution
  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-65660

Remediation

  • Apply Microsoft’s security updates for CVE-2026-65660 immediately and ensure all applicable SharePoint update packages are installed.
  • Verify patched build levels: 16.0.5565.1001 (SharePoint 2016), 16.0.10417.20198 (SharePoint 2019), and 16.0.19725.20522 (Subscription Edition).
  • Restrict internet-facing and anonymous access to SharePoint servers wherever it is not required.
  • Review and remove unnecessary low-privileged SharePoint accounts and enforce least-privilege access.
  • Monitor SharePoint and IIS logs for suspicious POST requests, unusual Web Part markup, encoded XAML, and unexpected ToolPane activity.
  • Hunt for abnormal SharePoint worker-process behavior, unexpected child processes, and anomalous .NET assemblies.
  • Inspect endpoint, PowerShell, and Windows Event logs for signs of remote code execution, credential theft, or lateral movement.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.