Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Malware Tracking Tool Discovers Autonomous AI Malware
September 22, 2026
Critical Microsoft SharePoint RCE Vulnerability CVE-2023-29357 Patched
September 22, 2026
Critical Linux KVM/arm64 Vulnerability Lets Attackers Escape VMs, Gain Host Access
September 22, 2026
Home/CyberSecurity News/Critical Microsoft SharePoint RCE Vulnerability CVE-2023-29357 Patched
CyberSecurity News

Critical Microsoft SharePoint RCE Vulnerability CVE-2023-29357 Patched

Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-65660, affecting Microsoft SharePoint has been publicly disclosed. The flaw impacts SharePoint 2016, 2019, and...

Emy Elsamnoudy
Emy Elsamnoudy
September 22, 2026 3 Min Read
3 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability, CVE-2026-65660, affecting Microsoft SharePoint has been publicly disclosed.
  • The flaw impacts SharePoint 2016, 2019, and Subscription Edition, with SharePoint 2013 also vulnerable but past end-of-life.
  • Microsoft released patches on August 11, 2026, which administrators must apply immediately.
  • The vulnerability allows pre-authentication RCE, meaning attackers can execute code without prior authentication.

Critical SharePoint RCE Vulnerability CVE-2026-65660 Exposed

Microsoft has addressed a critical remote code execution (RCE) vulnerability, identified as CVE-2026-65660, within its SharePoint platform. While initially assessed as less likely to be exploited, detailed technical information regarding the flaw has now entered the public domain, elevating the urgency for immediate patching across affected organizations.

Table Of Content

  • Key Takeaways
  • Critical SharePoint RCE Vulnerability CVE-2026-65660 Exposed
  • Vulnerability Details and Impact
  • Patch Availability and Recommendations
  • What You Should Do

Vulnerability Details and Impact

The vulnerability reportedly allows for pre-authentication remote code execution, meaning an attacker could execute arbitrary code on a vulnerable SharePoint server without needing to authenticate first. This type of flaw presents a severe risk, as it significantly lowers the bar for exploitation.

Microsoft’s official advisory confirms that SharePoint 2016, SharePoint 2019, and SharePoint Subscription Edition are all impacted by CVE-2026-65660. The researcher who discovered the vulnerability also noted that SharePoint 2013 is susceptible, although this version reached its end-of-support in April 2023, meaning no official patches will be released for it.

Patch Availability and Recommendations

Microsoft issued security fixes for CVE-2026-65660 on August 11, 2026. The specific patched build levels are:

  • SharePoint 2016: 16.0.5565.1001
  • SharePoint 2019: 16.0.10417.20198
  • SharePoint Subscription Edition: 16.0.19725.20522

Microsoft’s advisory mandates customer action, emphasizing that all applicable update packages must be installed. For administrators managing SharePoint 2016, it may be necessary to install both listed packages to fully mitigate the risk.

Organizations still relying on SharePoint 2013 face a critical security posture. Given its end-of-life status, a security update is highly improbable. These organizations should prioritize migration to a supported version or implement stringent isolation measures to protect their data and systems from potential exploitation.

While Microsoft initially rated exploitation as “less likely” and stated that the vulnerability had not been publicly disclosed or exploited at the time of publication, the public availability of detailed technical information necessitates a reassessment of that risk. Administrators should consider the threat immediate and act accordingly.

What You Should Do

  • Patch Immediately: Apply the latest security updates for SharePoint 2016, 2019, and Subscription Edition without delay. Ensure all applicable packages are installed.
  • Restrict Access: Limit internet-facing exposure for SharePoint servers and restrict anonymous access where possible.
  • Audit Accounts: Conduct a thorough audit of all low-privilege accounts to minimize potential lateral movement post-compromise.
  • Hunt for Anomalies: Proactively search for suspicious POST requests containing unusual Web Part markup or encoded XAML.
  • Monitor Worker Processes: Examine SharePoint worker-process behavior for unexpected child processes or anomalous assemblies.
  • Memory Forensics: Be prepared to perform volatile memory analysis, as in-memory implants may leave minimal disk-based evidence.
  • Preserve Telemetry: Before restarting any potentially compromised SharePoint servers during an investigation, preserve all IIS, ULS, Windows event, PowerShell, and endpoint telemetry logs.
  • Migrate SharePoint 2013: Organizations running SharePoint 2013 must prioritize migration to a supported version or implement robust isolation strategies due to the lack of official security updates.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Linux KVM/arm64 Vulnerability Lets Attackers Escape VMs, Gain Host Access

Next Post

AI Malware Tracking Tool Discovers Autonomous AI Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Veeam Agent for Windows Flaw (CVE-2023-27532) Actively Exploited
September 22, 2026
BambooToken Linux Backdoor Uses MQTT for Remote Shell and File Exfiltration
September 22, 2026
Cloned Websites Deliver Chrome, Windows Zero-Day Exploits
September 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us