type: cve · created: 2026-09-26 · updated: 2026-09-26 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
Improper control of generation of code (code injection) in Microsoft Office SharePoint allows an authorised attacker to execute code over a network. CISA added CVE-2026-65660 to the Known Exploited Vulnerabilities catalog on 25 September 2026 on evidence of active exploitation, with a remediation deadline of 28 September — a three-day federal window rather than the three weeks a KEV entry usually allows. The flaw carries a CVSS 3.1 base score of 8.8 (vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and it is the higher-rated of the two flaws added that day.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-65660 |
| CVSS | 8.8 (CVSS 3.1, HIGH) |
| Vendor / product | Microsoft / Office SharePoint |
| Reported | 2026-09-26 |