A security flaw in Microsoft SharePoint is being actively exploited by attackers, and Microsoft has confirmed real-world attacks are already underway.
- What it is: A vulnerability (CVE-2026-65660) in SharePoint lets an attacker who already has some access to the system run their own code on the server, gaining far deeper control than they should have.
- Who is affected: Organisations running SharePoint Server, including many businesses that host internal documents, intranets or client portals on it.
- What the risk is: Microsoft has confirmed it has evidence of attacks exploiting this flaw. A successful attack could let someone take over the server hosting your SharePoint data.
- What to do: Apply the latest Microsoft security updates as a priority. Overseas federal agencies have been given until 28 September 2026 to patch, which is a useful guide to how urgent this is.
We recommend confirming with your IT provider that every SharePoint server in your environment is fully patched.
Source: The Hacker News