Microsoft SharePoint vulnerability CVE-2026-65660 is now being exploited in attacks, according to reporting that cites its addition to CISA’s Known Exploited Vulnerabilities catalog. CISA’s KEV inclusion is a strong signal for defenders to prioritize remediation and to confirm that externally reachable SharePoint servers are in scope.

Security teams should apply Microsoft’s current guidance, hunt for anomalous SharePoint activity, and check for changes to accounts, web shells, or scheduled tasks. Teams should avoid assuming that patching alone resolves a prior compromise; post-patch investigation remains important where exploitation is suspected.

Source: SecurityWeek

By Allan