Interestana
Home/News/SharePoint Flaw Allows RCE, Not Just Spoofing
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

SharePoint Flaw Allows RCE, Not Just Spoofing

SharePoint Flaw Allows RCE, Not Just Spoofing

A critical vulnerability in Microsoft SharePoint Server, initially categorized by Microsoft as a spoofing flaw with a Common Vulnerability Scoring System (CVSS) score of 6.5, has been revealed to enable authenticated remote code execution (RCE). Full technical details of this vulnerability were published today by Dinh Ho Anh Khoa, a researcher at Viettel Cyber Security. The flaw, assigned the identifier CVE-2026-65660, impacts multiple versions of SharePoint Server, specifically SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft has since released patches to address this vulnerability, urging users to apply them promptly to mitigate the risk of exploitation.

Viettel Cyber Security's detailed analysis indicates that the vulnerability, when exploited by an authenticated attacker, allows for the execution of arbitrary code on the affected SharePoint server. This capability is significantly more severe than a spoofing flaw, which typically only allows an attacker to impersonate another user or system. Remote code execution grants an attacker the ability to run commands, install programs, and access or modify data on the compromised server, potentially leading to a full system takeover. The CVSS score of 6.5, while considered "high," does not fully reflect the potential impact of RCE, which is often rated with scores of 9.0 or higher.

The researcher's findings highlight a common challenge in vulnerability management: the initial assessment of a flaw's severity may not always capture its full exploitability or impact. Microsoft's classification of CVE-2026-65660 as a spoofing issue suggests an initial underestimation of its capabilities. The subsequent disclosure of its RCE potential underscores the importance of thorough analysis by independent security researchers and the need for vendors to re-evaluate vulnerabilities if new exploit information emerges. Organizations relying on SharePoint Server are advised to prioritize the application of the provided patches to safeguard their systems against this authenticated RCE threat.

SharePoint Server is a widely used collaboration and document management platform within many enterprises, making vulnerabilities affecting it a significant concern for IT security professionals. The platform's role in storing and managing sensitive corporate data means that a successful RCE attack could have far-reaching consequences, including data breaches, service disruptions, and reputational damage. The fact that the vulnerability requires authentication means that an attacker would first need to compromise valid user credentials before being able to exploit CVE-2026-65660. This adds a layer of complexity to the attack chain but does not diminish the severity of the RCE capability once access is gained.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next