External risk intelligence

SharePoint Server Code Injection Allows Network Code Execution.

CVE advisoryKnown Exploit

CVE-2026-65660

Microsoft SharePoint is commonly deployed as an internet-facing web application, portal, or collaboration service. Given its role as a centralized enterprise platform, it is frequently exposed to network access to facilitate remote collaboration and external document sharing, making it a likely candidate for public internet reachability.

Code Injection

Microsoft Sharepoint Server

before 16.0.19725.2052220162019

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a high-severity vulnerability in Microsoft SharePoint Server that could allow an authorized attacker to execute code over a network. The concern centers on the potential for unauthorized code execution, which may have broad implications for systems that are accessible externally. The main concern is confirming relevance and exposure for your specific environment.

  • Attackers can inject and run code remotely.
  • It impacts a core collaboration and document management platform.
  • Verify if your SharePoint instances are externally accessible.

Attack Path

How an attacker could exploit the issue

An attacker with legitimate access to a Microsoft Office SharePoint system could exploit this vulnerability by triggering a code injection flaw. This could allow them to execute arbitrary code over the network, potentially leading to a compromise of the server's functionality.

  • Requires authorized user access.
  • Triggers via improper code generation.
  • Risks remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authorized attacker to execute code on a network-accessible Microsoft Office SharePoint server, potentially impacting its services and any data it processes or stores, when supported by the advisory's conditions.

  • Server code execution could be impacted.
  • Code injection may occur over a network.
  • Compromise of server integrity is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Microsoft SharePoint, including infrastructure, platform, and security operations, should initiate a comprehensive asset inventory to identify all instances of the affected technology. The immediate practical step is to confirm the network reachability and business criticality of each SharePoint deployment to prioritize remediation efforts and engage the accountable owners.

  • Identify and inventory all SharePoint instances.
  • Verify external access and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft SharePoint Server?

Microsoft SharePoint Server is a centralized enterprise platform used primarily for document management, team collaboration, and hosting internal websites. Organizations rely on it to store sensitive data and facilitate remote work, making it a critical component of corporate infrastructure that often bridges the gap between internal resources and distributed teams.

What does this code injection vulnerability mean?

This vulnerability is classified as CWE-94, which refers to the improper control of code generation. Essentially, the software fails to properly filter or neutralize data provided by a user, allowing that input to be executed as part of a command or script. In the context of CVE-2026-65660, this flaw grants an attacker the ability to force the server to run unauthorized commands or software.

Do I need to be a system administrator to trigger this bug?

Yes, successful exploitation requires the attacker to have some form of authorized access to the SharePoint environment. This means an anonymous, unauthenticated user cannot simply reach out and trigger the code execution. The vulnerability is not triggered by standard web requests from the general public; it relies on someone who already possesses a level of legitimate access to the system.

How do I know if my SharePoint instance is at risk?

You should consider the risk based on the accessibility of your servers. According to the Halo Surface Signal, Microsoft SharePoint is frequently deployed as an internet-facing service to support remote collaboration, which increases the likelihood of external reachability. If your deployment is accessible from the public internet rather than restricted to a private internal network, it is a primary candidate for this threat.

When should I prioritize patching my SharePoint servers?

Prioritization should begin immediately by creating an inventory of all your SharePoint deployments. Once you have identified which servers are running the affected versions, assess their network reachability and business criticality. Servers that are accessible over the internet or house highly sensitive data should be at the top of your list for applying the official vendor updates.

References