AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
What it means
La Canadian Centre for Cyber Security ha rilevato l'exploit attivo di una vulnerabilità (CVE-2026-65660) in Microsoft SharePoint Server. Questa vulnerabilità, di tipo Code Injection, consente a un attaccante autenticato di eseguire codice arbitrario. Se combinata con altre vulnerabilità, permette esecuzione remota di codice senza autenticazione. Le versioni interessate includono SharePoint Enterprise Server 2016 e SharePoint Server 2019. La patch è disponibile per queste versioni.
Why it matters
Per le PMI italiane, questa vulnerabilità rappresenta un rischio significativo per la sicurezza dei dati e delle infrastrutture IT. L'exploit attivo e la possibilità di esecuzione remota di codice possono portare a compromissioni critiche, perdita di dati e interruzione delle operazioni. La mancanza di patch e di misure di sicurezza potrebbe esporre l'azienda a attacchi mirati.
Recommended actions
- Upgrade affected Microsoft SharePoint instances to the fixed version: 16.0.5565.1001 for SharePoint Enterprise Server 2016
- Apply the latest Microsoft security updates to all SharePoint Server deployments
- Restrict or eliminate direct internet exposure of SharePoint servers where possible
- Review SharePoint environments for unnecessary or inactive accounts and remove them
- Enforce multi-factor authentication (MFA) for administrators and other privileged users
- Enable Antimalware Scan Interface (AMSI) integration for SharePoint web applications
- Conduct ongoing log and security monitoring of SharePoint, IIS, endpoint security, and authentication logs
Potential operational benefits
- Riduzione della superficie esposta
- Maggiore controllo sugli accessi
- Rilevamento precoce delle attività sospette
- Minimizzazione del rischio di compromissione
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Number: AL26-023 Date: September 24, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint Server Footnote 1 . In response to the Microsoft security advisory, released on August 11, 2026 Footnote 2 , the Cyber Centre issued AV26-804 Update 3 Footnote 3 on September 24, 2026. Tracked as CVE-2026- 65660 Footnote 4 , this vulnerability is an Improper Control of Generation of Code ('Code Injection') (CWE-94) Footnote 5 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers. Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre-authentication remote code execution on SharePoint servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates may therefore face an elevated risk of compromise. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected products Affected versions Fixed Versions Microsoft SharePoint Enterprise Server 2016 All versions prior to 16.0.5565.1001 Version 16.0.5565.1001 Microsoft SharePoint Server 2019 All Versions prior to 16.0.10417.20198 Version
- Source
- Canadian Centre for Cyber Security (Canada)
- Publishing entity
- Canadian Centre for Cyber Security
- Entity type
- National CSIRT
- Area
- North America · CA
- Original language
- en · translation in preparation
- Publication
- 24/09/2026 19:12
- MITRE ATT&CK
- T1059.001, T1562
- CVE
- CVE-2026-65660
- Stated country
- CA
Affected products and versions
The collector will check NVD and the available official vendor advisories.