<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftsharepoint_server2016/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 19:51:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftsharepoint_server2016/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of Code Injection Vulnerability in Microsoft SharePoint Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-sharepoint-rce/</link><pubDate>Thu, 24 Sep 2026 19:51:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sharepoint-rce/</guid><description>Authenticated attackers are actively exploiting CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint Server, to execute arbitrary code, with potential for pre-authentication RCE when chained with other flaws.</description><content:encoded><![CDATA[<p>The Canadian Centre for Cyber Security has confirmed active exploitation of CVE-2026-65660, a code injection vulnerability (CWE-94) affecting Microsoft SharePoint Server. The flaw permits an authenticated attacker to achieve arbitrary code execution on vulnerable instances. Crucially, when chained with other SharePoint vulnerabilities, attackers can reach pre-authentication remote code execution (RCE) on servers that allow anonymous access. This poses a severe risk to organizations running legacy or unpatched SharePoint deployments. Microsoft SharePoint Enterprise Server 2016 and Server 2019 reached end-of-life on July 15, 2026, and remain highly susceptible. Defenders must prioritize upgrading to the specified fixed versions to remediate the vulnerability and mitigate the risk of ongoing exploitation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify internet-facing Microsoft SharePoint instances.</li>
<li>If anonymous access is enabled, the attacker chains existing auxiliary vulnerabilities to bypass initial authentication.</li>
<li>Attacker targets the specific code injection vector defined by CVE-2026-65660.</li>
<li>The malicious request triggers the underlying vulnerability, allowing for code execution within the SharePoint application context.</li>
<li>Attacker executes arbitrary commands, potentially deploying a web shell to maintain persistence (e.g., via T1505.003).</li>
<li>Attacker leverages the elevated application context to perform further privilege escalation or move laterally within the server environment.</li>
<li>Attacker achieves the final objective, which may include data exfiltration or internal network reconnaissance.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to gain full code execution on affected SharePoint servers. This can lead to total system compromise, unauthorized access to sensitive internal data, and the establishment of persistent backdoors within the organization's network. Given that many SharePoint instances store critical business and enterprise data, the impact of a successful breach is significant. Organizations running EOL versions (2016 and 2019) are at a particularly elevated risk, as they no longer receive standard support and may lack defense-in-depth protections.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate upgrade of all SharePoint instances to the fixed versions listed below. Enable Antimalware Scan Interface (AMSI) integration for SharePoint web applications and set the scan mode to 'Full' to improve detection of malicious payloads. Restrict access to management interfaces like SharePoint Central Administration and ensure all internet-facing instances are shielded from unnecessary exposure. Monitor IIS and SharePoint logs for anomalous administrative behavior, unauthorized web part modifications, and unexpected deserialization activity that may signal exploitation.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>rce</category><category>exploitation</category><category>sharepoint</category></item></channel></rss>