EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660

Official source
EudorIA operational summary

What it means

Priority 95/100

La Canadian Centre for Cyber Security ha rilevato l'exploit attivo di una vulnerabilità (CVE-2026-65660) in Microsoft SharePoint Server. Questa vulnerabilità, di tipo Code Injection, consente a un attaccante autenticato di eseguire codice arbitrario. Se combinata con altre vulnerabilità, permette esecuzione remota di codice senza autenticazione. Le versioni interessate includono SharePoint Enterprise Server 2016 e SharePoint Server 2019. La patch è disponibile per queste versioni.

Why it matters

Per le PMI italiane, questa vulnerabilità rappresenta un rischio significativo per la sicurezza dei dati e delle infrastrutture IT. L'exploit attivo e la possibilità di esecuzione remota di codice possono portare a compromissioni critiche, perdita di dati e interruzione delle operazioni. La mancanza di patch e di misure di sicurezza potrebbe esporre l'azienda a attacchi mirati.

Potential operational benefits

  • Riduzione della superficie esposta
  • Maggiore controllo sugli accessi
  • Rilevamento precoce delle attività sospette
  • Minimizzazione del rischio di compromissione
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMFA / IdentitàHardeningMonitoraggio / SIEM
AudienceITCISO
Information centre

Translation in progress

Canadian Centre for Cyber Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Number: AL26-023 Date: September 24, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint Server Footnote 1 . In response to the Microsoft security advisory, released on August 11, 2026 Footnote 2 , the Cyber Centre issued AV26-804 Update 3 Footnote 3 on September 24, 2026. Tracked as CVE-2026- 65660 Footnote 4 , this vulnerability is an Improper Control of Generation of Code ('Code Injection') (CWE-94) Footnote 5 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers. Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre-authentication remote code execution on SharePoint servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates may therefore face an elevated risk of compromise. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected products Affected versions Fixed Versions Microsoft SharePoint Enterprise Server 2016 All versions prior to 16.0.5565.1001 Version 16.0.5565.1001 Microsoft SharePoint Server 2019 All Versions prior to 16.0.10417.20198 Version

Source
Canadian Centre for Cyber Security (Canada)
Publishing entity
Canadian Centre for Cyber Security
Entity type
National CSIRT
Area
North America · CA
Original language
en · translation in preparation
Publication
24/09/2026 19:12
MITRE ATT&CK
T1059.001, T1562
CVE
CVE-2026-65660
Stated country
CA
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source