Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

A SharePoint Flaw Rated Medium Turned Out to Be Remote Code Execution Under Active Attack

What Happened

CISA added SharePoint flaw CVE-2026-65660 to its Known Exploited Vulnerabilities catalog on September 25 with a federal patch deadline of September 28. The bug is a code injection flaw rated CVSS 8.8. Microsoft first labeled it a spoofing issue, then corrected the advisory to remote code execution and confirmed attacks as of September 25. Attackers need an authenticated account with low privileges. Researchers saw two-stage attempts to plant web shells. Microsoft has not named the attacker or the victims. Patches shipped in August. See The Hacker News for the full report and the MikroTik flaw added alongside it.

Why This Matters for Canadian Organizations

The severity mislabel matters here. Teams triage by category and score, and a spoofing flaw with a medium rating sits low in most queues. Many Canadian organizations run on-premises SharePoint for document management, including provincial ministries, school boards, health authorities, and law firms. Those servers hold sensitive records, and a low-privilege account is easy to obtain through phishing or credential stuffing.

A web shell on a SharePoint server gives an attacker a foothold inside the internal network. For organizations covered by PIPEDA or provincial health privacy law, stolen documents trigger breach notification duties. Canadian federal departments follow their own patch timelines, but the same exploitation window applies to every unpatched server.

What to Do

Confirm the August SharePoint updates are installed on every farm server. Raise CVE-2026-65660 to critical priority in your vulnerability tracker. Search web directories for unexpected files, review IIS logs for unusual requests from low-privilege accounts, and check for new scheduled tasks or child processes spawned by the SharePoint worker process. Audit accounts with SharePoint access and disable those no longer needed. Enforce multi-factor authentication, since exploitation depends on a valid login.

More vulnerability coverage lives in our TechTalk section and today’s News roundup.

Enjoy this article? Don’t forget to share.