Critical Microsoft SharePoint RCE Vulnerability CVE-2023-29357 Patched
Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-65660, affecting Microsoft SharePoint has been publicly disclosed. The flaw impacts SharePoint 2016, 2019, and...
Key Takeaways
- A critical remote code execution (RCE) vulnerability, CVE-2026-65660, affecting Microsoft SharePoint has been publicly disclosed.
- The flaw impacts SharePoint 2016, 2019, and Subscription Edition, with SharePoint 2013 also vulnerable but past end-of-life.
- Microsoft released patches on August 11, 2026, which administrators must apply immediately.
- The vulnerability allows pre-authentication RCE, meaning attackers can execute code without prior authentication.
Critical SharePoint RCE Vulnerability CVE-2026-65660 Exposed
Microsoft has addressed a critical remote code execution (RCE) vulnerability, identified as CVE-2026-65660, within its SharePoint platform. While initially assessed as less likely to be exploited, detailed technical information regarding the flaw has now entered the public domain, elevating the urgency for immediate patching across affected organizations.
Table Of Content
Vulnerability Details and Impact
The vulnerability reportedly allows for pre-authentication remote code execution, meaning an attacker could execute arbitrary code on a vulnerable SharePoint server without needing to authenticate first. This type of flaw presents a severe risk, as it significantly lowers the bar for exploitation.
Microsoft’s official advisory confirms that SharePoint 2016, SharePoint 2019, and SharePoint Subscription Edition are all impacted by CVE-2026-65660. The researcher who discovered the vulnerability also noted that SharePoint 2013 is susceptible, although this version reached its end-of-support in April 2023, meaning no official patches will be released for it.
Patch Availability and Recommendations
Microsoft issued security fixes for CVE-2026-65660 on August 11, 2026. The specific patched build levels are:
- SharePoint 2016: 16.0.5565.1001
- SharePoint 2019: 16.0.10417.20198
- SharePoint Subscription Edition: 16.0.19725.20522
Microsoft’s advisory mandates customer action, emphasizing that all applicable update packages must be installed. For administrators managing SharePoint 2016, it may be necessary to install both listed packages to fully mitigate the risk.
Organizations still relying on SharePoint 2013 face a critical security posture. Given its end-of-life status, a security update is highly improbable. These organizations should prioritize migration to a supported version or implement stringent isolation measures to protect their data and systems from potential exploitation.
While Microsoft initially rated exploitation as “less likely” and stated that the vulnerability had not been publicly disclosed or exploited at the time of publication, the public availability of detailed technical information necessitates a reassessment of that risk. Administrators should consider the threat immediate and act accordingly.
What You Should Do
- Patch Immediately: Apply the latest security updates for SharePoint 2016, 2019, and Subscription Edition without delay. Ensure all applicable packages are installed.
- Restrict Access: Limit internet-facing exposure for SharePoint servers and restrict anonymous access where possible.
- Audit Accounts: Conduct a thorough audit of all low-privilege accounts to minimize potential lateral movement post-compromise.
- Hunt for Anomalies: Proactively search for suspicious POST requests containing unusual Web Part markup or encoded XAML.
- Monitor Worker Processes: Examine SharePoint worker-process behavior for unexpected child processes or anomalous assemblies.
- Memory Forensics: Be prepared to perform volatile memory analysis, as in-memory implants may leave minimal disk-based evidence.
- Preserve Telemetry: Before restarting any potentially compromised SharePoint servers during an investigation, preserve all IIS, ULS, Windows event, PowerShell, and endpoint telemetry logs.
- Migrate SharePoint 2013: Organizations running SharePoint 2013 must prioritize migration to a supported version or implement robust isolation strategies due to the lack of official security updates.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.