AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660
Cosa significa
La Canadian Centre for Cyber Security ha rilevato l'exploit attivo di una vulnerabilità (CVE-2026-65660) in Microsoft SharePoint Server. Questa vulnerabilità, di tipo Code Injection, consente a un attaccante autenticato di eseguire codice arbitrario. Se combinata con altre vulnerabilità, permette esecuzione remota di codice senza autenticazione. Le versioni interessate includono SharePoint Enterprise Server 2016 e SharePoint Server 2019. La patch è disponibile per queste versioni.
Perché conta
Per le PMI italiane, questa vulnerabilità rappresenta un rischio significativo per la sicurezza dei dati e delle infrastrutture IT. L'exploit attivo e la possibilità di esecuzione remota di codice possono portare a compromissioni critiche, perdita di dati e interruzione delle operazioni. La mancanza di patch e di misure di sicurezza potrebbe esporre l'azienda a attacchi mirati.
Azioni consigliate
- Upgrade affected Microsoft SharePoint instances to the fixed version: 16.0.5565.1001 for SharePoint Enterprise Server 2016
- Apply the latest Microsoft security updates to all SharePoint Server deployments
- Restrict or eliminate direct internet exposure of SharePoint servers where possible
- Review SharePoint environments for unnecessary or inactive accounts and remove them
- Enforce multi-factor authentication (MFA) for administrators and other privileged users
- Enable Antimalware Scan Interface (AMSI) integration for SharePoint web applications
- Conduct ongoing log and security monitoring of SharePoint, IIS, endpoint security, and authentication logs
Benefici operativi potenziali
- Riduzione della superficie esposta
- Maggiore controllo sugli accessi
- Rilevamento precoce delle attività sospette
- Minimizzazione del rischio di compromissione
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Number: AL26-023 Date: September 24, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitation of a vulnerability affecting Microsoft SharePoint Server Footnote 1 . In response to the Microsoft security advisory, released on August 11, 2026 Footnote 2 , the Cyber Centre issued AV26-804 Update 3 Footnote 3 on September 24, 2026. Tracked as CVE-2026- 65660 Footnote 4 , this vulnerability is an Improper Control of Generation of Code ('Code Injection') (CWE-94) Footnote 5 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an authenticated attacker to execute arbitrary code on vulnerable SharePoint servers. Chained with other SharePoint vulnerabilities, this vulnerability can achieve pre-authentication remote code execution on SharePoint servers configured to permit anonymous access. Organizations that have not fully applied prior SharePoint security updates may therefore face an elevated risk of compromise. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected products Affected versions Fixed Versions Microsoft SharePoint Enterprise Server 2016 All versions prior to 16.0.5565.1001 Version 16.0.5565.1001 Microsoft SharePoint Server 2019 All Versions prior to 16.0.10417.20198 Version
- Fonte
- Canadian Centre for Cyber Security (Canada)
- Entità pubblicatrice
- Canadian Centre for Cyber Security
- Tipo entità
- CSIRT nazionale
- Area
- North America · CA
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 24/09/2026 19:12
- MITRE ATT&CK
- T1059.001, T1562
- CVE
- CVE-2026-65660
- Paese indicato
- CA
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.