Microsoft's patched CVE-2026-65660 vulnerability in on-premises SharePoint Server enables authenticated, low-privileged users to execute arbitrary code remotely. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition: attackers can inject Register directives into ToolPane web-part markup, bypass SafeControls validation, load arbitrary .NET classes, and trigger deserialization via XamlServices.Parse().
Microsoft initially categorized the issue as authenticated spoofing with a CVSS score of 6.5, while the NVD rates it 8.8 and a separate Microsoft record identifies it as RCE. Updates released August 11 disable the vulnerable function by default; organizations should apply them promptly, particularly because public exploit material includes an in-memory webshell payload. No active exploitation has been reported and CISA has not listed the CVE as known exploited, but unsupported SharePoint 2013 may remain exposed to the underlying technique.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft updated its CVE-2026-65660 record to state that an authorized attacker could execute code, replacing its earlier characterization of the flaw as a spoofing vulnerability. Both versions associated the issue with CWE-94 code injection.
Microsoft released security updates for CVE-2026-65660 affecting SharePoint Server 2016, 2019, and Subscription Edition. The update fixes the ToolPane directive-injection issue and disables the vulnerable function by default.
Microsoft's June 9, 2026 update fixed the separate authentication weakness that could be chained with CVE-2026-65660 for pre-authentication RCE on SharePoint servers permitting anonymous page access.
Dinh Ho Anh Khoa demonstrated the ToolShell SharePoint exploit chain at Pwn2Own Berlin.
SharePoint Server 2013 reached end of support and no longer receives security updates. The researcher later reported that the underlying CVE-2026-65660 technique also affects this unsupported version.
Dinh Ho Anh Khoa published technical details and working exploit markup showing how unsafe ToolPane Register-directive reconstruction bypasses SafeControls validation, permits arbitrary .NET class loading, and can lead to code execution through deserialization. The published material includes an in-memory webshell payload and documents a pre-authentication chain where anonymous access is enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.