Microsoft SharePoint Vulnerability Misclassified as Spoofing Enables Authenticated RCE
A SharePoint Server vulnerability initially categorized as a spoofing flaw by Microsoft was revealed to enable authenticated remote code execution (RCE), with technical details disclosed by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects multiple SharePoint versions and allows code injection through unsafe control handling, though no widespread exploitation has been reported.
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.
The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
*** END OF TRANSMISSION ***