{"id":1905,"date":"2026-09-23T10:22:01","date_gmt":"2026-09-23T04:52:01","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1905"},"modified":"2026-09-24T11:45:35","modified_gmt":"2026-09-24T06:15:35","slug":"sharepoint-cve-2026-65660-authenticated-rce","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/","title":{"rendered":"SharePoint CVE-2026-65660: Why Teams Should Reassess Patch Priority"},"content":{"rendered":"<p>A patch queue is only as useful as the information behind it. Technical details reported on September 22, 2026, describe SharePoint CVE-2026-65660 as enabling authenticated code execution despite its initial spoofing classification.<\/p>\n<p>The reported weakness involves unsafe processing of server-side controls. For administrators, the practical issue is whether earlier triage decisions still match the demonstrated impact. A lower initial severity assessment should not replace a review of actual exposure.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is Microsoft SharePoint Server?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tMicrosoft SharePoint Server is collaboration software that organizations operate on their own infrastructure. Teams use it to organize documents, publish intranet content, and support shared business processes. Administrators manage the servers, configuration, permissions, and updates that keep those services available.<\/p>\n<p>Its security importance depends on the deployment. A farm may hold sensitive documents or connect to other internal services. Consequently, a server compromise could affect information and resources available to the compromised process.<\/p>\n<p>SharePoint Server is distinct from SharePoint Online, the hosted Microsoft 365 service. This article concerns the server product. It does not identify a particular customer as a victim or attribute exploitation to a named threat actor.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<p>The disclosure describes a SharePoint authenticated RCE risk with specific prerequisites.<\/p>\n<table>\n<thead>\n<tr>\n<th>Area<\/th>\n<th>Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Affected editions<\/td>\n<td>SharePoint Server 2016, SharePoint Server 2019, and Subscription Edition.<\/td>\n<\/tr>\n<tr>\n<td>Classification discrepancy<\/td>\n<td>The initial spoofing assessment carried a 6.5 score; public reporting identifies an 8.8 NVD assessment.<\/td>\n<\/tr>\n<tr>\n<td>Attack mechanism<\/td>\n<td>Unsafe quote handling during <code>Register<\/code> directive reconstruction can undermine SafeControls checks and enable code execution through deserialization.<\/td>\n<\/tr>\n<tr>\n<td>Unauthenticated chain<\/td>\n<td>A separate, previously patched authentication bypass and anonymous page access are additional prerequisites.<\/td>\n<\/tr>\n<tr>\n<td>Exploitation status<\/td>\n<td>September 22 reporting did not identify exploitation in the wild.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These details describe a demonstrated capability, not confirmed credential theft, ransomware deployment, or persistent access in a victim environment. The available reporting also does not establish an MFA bypass by this flaw alone.<\/p>\n<p>Microsoft\u2019s August 11, 2026, Subscription Edition security update explicitly lists this CVE among the vulnerabilities it addresses. Administrators should identify the applicable update for their exact edition and installed build. Follow the associated installation requirements rather than assuming that a successful operating system update also completes SharePoint remediation.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Secure-Device-Refresh-and-Retrieval-with-Hexnode.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How Hexnode Secures Client Data During Device Refresh and Retrieval<\/h4><p>Learn how Hexnode helps protect client data during device refresh, retrieval and reassignment.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/secure-device-refresh-retrieval\/\" aria-label=\"How Hexnode Secures Client Data During Device Refresh and Retrieval\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Why this matters<\/h2>\n<p>Collaboration servers connect everyday user activity with valuable business information. Code execution on one of these servers could expose documents or enable further access, depending on permissions and network reach. Those outcomes are potential consequences, not confirmed losses in this disclosure.<\/p>\n<p>Authentication narrows an attack path, but it does not repair the application behind it. An attacker with usable account access may still reach vulnerable functionality. Similarly, endpoint compliance cannot establish that a SharePoint farm has received every required update.<\/p>\n<p>Organizations therefore need separate checks for server remediation, account access, and device security. Patch management addresses the vulnerable code. Least privilege limits available access. Server monitoring and endpoint investigation help teams identify suspicious activity and respond when preventive controls fail.<\/p>\n<h2>How Hexnode can help<\/h2>\n<p>Hexnode can support the devices and access controls surrounding SharePoint operations. SharePoint patch deployment and server-side investigation remain essential responsibilities.<\/p>\n<h3>Hexnode UEM: Apply compliance requirements to administrator devices<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> can evaluate managed devices against configured requirements, including supported operating system, encryption, and application checks. IT teams can use these signals to identify administrator devices that fall below their security baseline.<\/p>\n<p>Through supported identity-provider integrations, device compliance can inform conditional access decisions. The identity provider applies the configured access policy. This can help restrict protected resources to devices that meet organizational requirements.<\/p>\n<p>For an on-premises SharePoint deployment, first verify that the relevant access route actually passes through the enforcement point. An integration protecting cloud applications does not automatically protect every local SharePoint URL or administrative interface. Test platform support, direct access paths, and emergency access before enforcement.<\/p>\n<p>These controls reduce exposure associated with noncompliant administrator devices. Hexnode UEM also manages <a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/help\/windows-patches-updates-management\/\" rel=\"noopener\">Windows OS-level updates<\/a> across laptops, desktops, and supported server fleets. However, it does not execute SharePoint application-layer cumulative updates (CUs) or build updates. Administrators must deploy those updates separately and verify the resulting SharePoint build. Device compliance alone does not confirm SharePoint\u2019s application patch status or remediate its vulnerability.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/thumbnail-for-infographics.webp?format=webp\" class=\"resource-box__image\" alt=\"thumbnail-for-infographics\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/thumbnail-for-infographics.webp?format=webp 961w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/thumbnail-for-infographics-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/thumbnail-for-infographics-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/thumbnail-for-infographics-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 961px) 100vw, 961px\" title=\"thumbnail-for-infographics\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Feature Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            How to use Hexnode macOS Gateway\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how you can migrate your macOS devices to Hexnode in just 8 steps.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/how-to-use-hexnode-macos-onboarder\/'>\n                            Get the Infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h3>Hexnode XDR: Support endpoint investigation and containment<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> documents response actions including device isolation, process termination, and file quarantine. On supported endpoints, these actions can help responders contain suspicious activity while investigating its scope.<\/p>\n<p>In this scenario, that role could include responding to a compromised administrator workstation or another affected endpoint. Isolation can restrict the device\u2019s network connectivity, while process termination can stop an identified malicious process.<\/p>\n<p>However, XDR investigation depends on supported platforms, deployed agents, and available telemetry. Do not assume that workstation coverage provides visibility into the SharePoint server itself. Confirm compatibility before including a server in any response workflow. Before extending XDR telemetry directly onto the SharePoint host, security teams should explicitly verify agent compatibility with its Windows Server OS version.<\/p>\n<p>Teams should also review SharePoint, web-server, and authentication logs through their existing investigation tools. Hexnode XDR should not be presented as having a verified detection rule for this CVE or automatically correlating every browser and identity event.<\/p>\n<h2>What security teams should do next<\/h2>\n<p>Revisit the patch decision for SharePoint CVE-2026-65660 using the reported execution risk and your deployment\u2019s exposure. Assign an owner to each farm and record the evidence needed to close remediation.<\/p>\n<ol>\n<li><strong>Verify the update.<\/strong> Identify each server\u2019s edition and build. Apply the appropriate security update and complete its installation requirements.<\/li>\n<li><strong>Check access paths.<\/strong> Review anonymous access, externally reachable interfaces, and administrative routes. Remove unnecessary exposure and confirm earlier security fixes.<\/li>\n<li><strong>Review possible compromise.<\/strong> Preserve relevant logs and investigate unexpected server activity. If evidence indicates compromise, follow incident-response procedures before declaring recovery complete.<\/li>\n<li><strong>Strengthen administrator endpoints.<\/strong> Apply suitable compliance requirements through Hexnode UEM to guard access routes, and confirm endpoint containment capabilities (isolation, process termination, file quarantine) through Hexnode XDR across supported admin endpoints.<\/li>\n<\/ol>\n<p>Keep server patch verification separate from device compliance reporting. Both matter, but they answer different questions. Close the remediation task only after validating the server update, reviewing access controls, and resolving any suspicious findings.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f<\/h5><p>Sign up for Hexnode to strengthen device compliance and secure administrator endpoints.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A patch queue is only as useful as the information behind it. Technical details reported&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1675,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16,21],"class_list":["post-1905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-windows","category-patch-management","product_category-unified-endpoint-management","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SharePoint CVE-2026-65660: Authenticated RCE Risk<\/title>\n<meta name=\"description\" content=\"CVE-2026-65660 in SharePoint was initially listed as spoofing but public details show authenticated remote code execution.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SharePoint CVE-2026-65660: Authenticated RCE Risk\" \/>\n<meta property=\"og:description\" content=\"CVE-2026-65660 in SharePoint was initially listed as spoofing but public details show authenticated remote code execution.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-23T04:52:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T06:15:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"SharePoint CVE-2026-65660: Why Teams Should Reassess Patch Priority\",\"datePublished\":\"2026-09-23T04:52:01+00:00\",\"dateModified\":\"2026-09-24T06:15:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/\"},\"wordCount\":1025,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp\",\"articleSection\":[\"Windows\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/\",\"name\":\"SharePoint CVE-2026-65660: Authenticated RCE Risk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp\",\"datePublished\":\"2026-09-23T04:52:01+00:00\",\"dateModified\":\"2026-09-24T06:15:35+00:00\",\"description\":\"CVE-2026-65660 in SharePoint was initially listed as spoofing but public details show authenticated remote code execution.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Cisco FMC Exploits Move From Edge Access to Qilin Ransomware and Cyclops Blink\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/sharepoint-cve-2026-65660-authenticated-rce\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SharePoint CVE-2026-65660: Why Teams Should Reassess Patch Priority\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SharePoint CVE-2026-65660: Authenticated RCE Risk","description":"CVE-2026-65660 in SharePoint was initially listed as spoofing but public details show authenticated remote code execution.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/","og_locale":"en_US","og_type":"article","og_title":"SharePoint CVE-2026-65660: Authenticated RCE Risk","og_description":"CVE-2026-65660 in SharePoint was initially listed as spoofing but public details show authenticated remote code execution.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-23T04:52:01+00:00","article_modified_time":"2026-09-24T06:15:35+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"SharePoint CVE-2026-65660: Why Teams Should Reassess Patch Priority","datePublished":"2026-09-23T04:52:01+00:00","dateModified":"2026-09-24T06:15:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/"},"wordCount":1025,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp","articleSection":["Windows","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/","url":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/","name":"SharePoint CVE-2026-65660: Authenticated RCE Risk","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp","datePublished":"2026-09-23T04:52:01+00:00","dateModified":"2026-09-24T06:15:35+00:00","description":"CVE-2026-65660 in SharePoint was initially listed as spoofing but public details show authenticated remote code execution.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Cisco-FMC-Exploits-Move-From-Edge-Access-to-Qilin-Ransomware-and-Cyclops-Blink.png?format=webp","width":1340,"height":700,"caption":"Cisco FMC Exploits Move From Edge Access to Qilin Ransomware and Cyclops Blink"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/sharepoint-cve-2026-65660-authenticated-rce\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"SharePoint CVE-2026-65660: Why Teams Should Reassess Patch Priority"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1905"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1905\/revisions"}],"predecessor-version":[{"id":1912,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1905\/revisions\/1912"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1675"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}