{"@odata.context":"https://api.msrc.microsoft.com/sug/v2.0/sugodata/v2.0/en-US/$metadata#vulnerability/$entity","id":"00000000-0000-0000-0000-0000b52986da","releaseDate":"2026-08-11T07:00:00-07:00","cveNumber":"CVE-2026-65660","cveTitle":"Microsoft SharePoint Server Remote Code Execution Vulnerability","releaseNumber":"2026-Aug","vulnType":"Security Vulnerability","latestRevisionDate":"2026-09-25T07:00:00-07:00","description":"<p>Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>\n","cweList":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"cweDetailsListForSearch":["cwe: CWE-94: Improper Control of Generation of Code ('Code Injection')","cweUrl: https://cwe.mitre.org/data/definitions/94.html"],"unformattedDescription":"Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.","mitreText":"CVE-2026-65660","mitreUrl":"https://www.cve.org/CVERecord?id=CVE-2026-65660","publiclyDisclosed":"No","exploited":"No","latestSoftwareReleaseId":2,"latestSoftwareRelease":"Exploitation Less Likely","olderSoftwareReleaseId":0,"denialOfService":"N/A","tag":"Microsoft Office SharePoint","issuingCna":"Microsoft","issuingCnaId":100000001,"severityId":100000001,"severity":"Important","impactId":100000005,"impact":"Remote Code Execution","langCode":"en-US","baseScore":"8.8","temporalScore":"7.7","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C","vectorStringSource":"Microsoft","isMariner":false,"customerActionRequired":true,"customerActionRequiredId":1,"cweDetailsList":[{"keys":["cwe","cweUrl"],"values":["CWE-94: Improper Control of Generation of Code ('Code Injection')","https://cwe.mitre.org/data/definitions/94.html"]}],"articles":[{"title":"Microsoft Office SharePoint Spoofing Vulnerability","articleType":"100000000","description":"<p>Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p>\n","ordinal":10000},{"title":"Microsoft Office SharePoint Remote Code Execution Vulnerability","articleType":"100000000","description":"<p>Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p>\n","ordinal":10000},{"articleType":"FAQ","description":"<p><strong>There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software?</strong></p>\n<p>Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.</p>\n","ordinal":10000},{"articleType":"FAQ","description":"<p><strong>I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?</strong></p>\n<p>Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.</p>\n","ordinal":10000},{"articleType":"FAQ","description":"<p><strong>How could an attacker exploit this vulnerability?</strong></p>\n<p>An authenticated attacker with low-level access to an affected server could send a specially crafted request to execute code on the server. User interaction is not required.</p>\n","ordinal":10000}],"revisions":[{"cveNumber":"CVE-2026-65660","version":1,"revisionDate":"2026-08-11T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Information published.</p>\n","unformattedDescription":"Information published.","notificationNeeded":false,"notificationSent":false,"sourceId":"65c06752-1586-f111-93a1-000d3ac5fb71"},{"cveNumber":"CVE-2026-65660","version":1.2,"revisionDate":"2026-09-25T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.</p>\n","unformattedDescription":"As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.","notificationNeeded":true,"notificationSent":true,"sourceId":"d69da849-16b9-f111-93a1-000d3ac5fb71"},{"cveNumber":"CVE-2026-65660","version":1.1,"revisionDate":"2026-08-27T07:00:00-07:00","initialDate":"0001-01-01T00:00:00Z","description":"<p>Updated Impact in the Security Updates table, CVE Title, and FAQs. This is an informational change only.</p>\n","unformattedDescription":"Updated Impact in the Security Updates table, CVE Title, and FAQs. This is an informational change only.","notificationNeeded":false,"notificationSent":false,"sourceId":"5a219cac-3da2-f111-93fe-000d3afbc7d7"}]}