Skip to content

CVE-2026-65660 explained: the Microsoft Sharepoint Server flaw and how to fix it

By Donovan Brown
September 27, 2026
8 sections
CVE-2026-65660 explained: the Microsoft Sharepoint Server flaw and how to fix it — Cyber Security article cover card from LayerLogix, with a warning alert icon
01

Introduction

CVE-2026-65660 is a flaw in Microsoft Sharepoint Server that lets an attacker run their own code on the server over your network. It is already listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, which means criminals are actively using it right now. If your business runs SharePoint Server on a computer, phone, or server you manage, keep reading.

02

Does this affect you?

The two-minute check

  1. Confirm whether your business runs Microsoft Sharepoint Server anywhere, including on the computer, phone, or server you run it on.
  2. Open SharePoint Central Administration and note the version and build number shown there.
  3. Ask whoever manages your servers if they've already applied the fix listed in the vendor advisory.

The record doesn't say which specific builds are affected, so treat any SharePoint Server instance as a candidate until you confirm otherwise.

When you can stop reading

If your business does not run Microsoft Sharepoint Server anywhere, this bug does not apply to you. You can close this tab.

03

How bad is it, honestly?

What the official record says

This flaw carries a Common Vulnerability Scoring System (CVSS) score of 8.8, rated HIGH (NVD). The scoring detail says an attacker only needs network access and a low-privileged account on the system. No one has to click anything or be tricked. If exploited, it can fully compromise the data, its integrity, and the server's availability.

The Exploit Prediction Scoring System (EPSS) puts the chance of exploitation in the next 30 days at 2.1%, in the 80.97th percentile compared to other flaws (EPSS). That is a low chance of exploitation in the next 30 days. EPSS is a forecast of activity, not a measure of how damaging the flaw would be if it did get used.

Despite that low forecast, this flaw is already on the CISA Known Exploited Vulnerabilities (KEV) catalog. That listing means real attacks have already been observed, not just theorized.

What that means for a business like yours

An attacker who already has some low-level login on your network could use this flaw to take over your SharePoint Server. From there they could read files, change them, or take the server offline. They don't need to fool an employee into clicking a link first. That's what makes this worth acting on even though the short-term forecast is low.

04

What to do about it, step by step

If someone else manages your IT

Send this to your provider. Keep it short and specific.

"Please confirm our SharePoint Server instances are patched against CVE-2026-65660. Please tell me the current version and build number. Please confirm the patch has been applied and tested."

If you manage it yourself

  1. Open the vendor advisory for CVE-2026-65660.
  2. Find the update it lists for your current SharePoint Server version.
  3. Download the update from the link the advisory provides.
  4. Schedule a maintenance window, since applying it may require a restart.
  5. Apply the update to the server.
  6. Restart the server if prompted.
  7. Confirm the version number changed in Central Administration afterward.
05

How long you have

The answer is now. This flaw sits on the CISA Known Exploited Vulnerabilities (KEV) catalog, with a federal remediation due date of September 28, 2026. That date applies to federal agencies, but it is a useful signal for everyone else too. Attackers are not waiting, so there's no reason for you to either.

06

How to check it actually worked

Don't just trust that an update ran. Open SharePoint Central Administration again and check the version and build number. Compare that number to what the vendor advisory lists as fixed. If your provider applied the patch, ask them to send you that version number in writing.

07

What to do if you can't patch right now

If you can't patch immediately, you can still reduce your exposure. Restrict which accounts can log into the SharePoint Server, since the attack requires a valid low-privileged login. Our privileged access management approach can help limit who holds that kind of account. This buys you time by shrinking the pool of usable logins, but it does not remove the flaw itself.

You can also limit network access to the server so fewer devices can reach it. This reduces opportunity but again does not fix the underlying code. Neither step replaces installing the vendor's patch. Treat these as a bridge, not a destination.

08

Frequently Asked Questions

Do I have to do anything if we only use this at home?

If you're a business owner running Microsoft Sharepoint Server on any computer, phone, or server, yes. This flaw does not care whether the server sits in an office or a spare room.

Will patching break anything?

The record doesn't say. Any server update carries some risk, which is why a scheduled maintenance window and a quick post-update check are worth doing.

How do I know if we've already been attacked?

The record doesn't include specific indicators. A third-party writeup describes observed exploitation attempts, which your IT team or provider can use to check your logs.

Does our regulatory obligation change because of this?

If you handle health records or financial data, this is a good moment to review your existing obligations under HIPAA or the FTC Safeguards Rule. Patching promptly supports those obligations either way.

What if we don't have anyone to check this for us?

That's exactly what a managed IT provider is for. LayerLogix offers managed IT services and cybersecurity support with 100% Texas-based support and business-hours support with after-hours emergency response. Request a free IT assessment or contact us to get your SharePoint Server checked.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call