Jessica Entwistle
September 28 2026
SecurityWeek reports that CISA has added CVE-2026-65660, a vulnerability affecting Microsoft SharePoint, to its Known Exploited Vulnerabilities catalogue. The agency has given federal agencies a patching deadline of 28 September, indicating that the flaw is now being actively exploited in the wild. While specific details of the exploitation activity have not been disclosed, the inclusion in CISA's KEV catalogue confirms that attackers are targeting this vulnerability in real-world environments. The rapid addition to the KEV catalogue suggests that the exploitation activity is significant enough to warrant urgent attention from organisations running affected SharePoint deployments.
SharePoint is a core collaboration and document management platform used across UK organisations in both on-premises and cloud-hosted configurations. Vulnerabilities in SharePoint can provide attackers with access to sensitive business documents, internal communications, and shared resources that underpin day-to-day operations. The fact that this vulnerability is now being exploited means organisations running affected versions are at immediate risk. For many businesses, SharePoint holds a significant portion of their institutional knowledge, project documentation, and operational data, making it a high-value target for attackers seeking to establish persistence or exfiltrate information. The operational impact of a SharePoint compromise can be substantial, affecting not only data confidentiality but also business continuity if attackers choose to encrypt or delete content. Organisations that rely on SharePoint for regulatory compliance, contract management, or customer data storage face additional risk if a breach results in unauthorised access to controlled information.
Organisations running Microsoft SharePoint should confirm that patches have been applied and review access logs for any unusual activity during the period before patching was completed. Review SharePoint permissions to ensure that access is appropriately restricted and that external sharing settings are configured in line with organisational policy. Consider implementing additional monitoring for SharePoint activity, including unusual file access patterns, privilege escalation attempts, or unexpected changes to site permissions. Organisations should also review who has administrative access to SharePoint environments and ensure that these accounts are subject to strong authentication and regular access reviews. Where SharePoint is used to store sensitive or regulated data, ensure that data classification and access controls are appropriately configured and that incident response plans include procedures for responding to SharePoint-related security incidents.
Source: SecurityWeek