Web_Logo
Remote Support
Office 365: SharePoint Flaw Under Active Attack
Home » Microsoft Updates  »  Office 365: SharePoint Flaw Under Active Attack

Office 365: SharePoint Flaw Under Active Attack

A security flaw in Microsoft SharePoint is being actively exploited by attackers, and Microsoft has confirmed real-world attacks are already underway.

  • What it is: A vulnerability (CVE-2026-65660) in SharePoint lets an attacker who already has some access to the system run their own code on the server, gaining far deeper control than they should have.
  • Who is affected: Organisations running SharePoint Server, including many businesses that host internal documents, intranets or client portals on it.
  • What the risk is: Microsoft has confirmed it has evidence of attacks exploiting this flaw. A successful attack could let someone take over the server hosting your SharePoint data.
  • What to do: Apply the latest Microsoft security updates as a priority. Overseas federal agencies have been given until 28 September 2026 to patch, which is a useful guide to how urgent this is.

We recommend confirming with your IT provider that every SharePoint server in your environment is fully patched.

Source: The Hacker News