**BREAKING: Microsoft SharePoint CVE-2026-65660 Added to CISA KEV; Active Exploitation Confirmed**

🛡️ **BREAKING: Microsoft SharePoint CVE-2026-65660 Added to CISA KEV; Active Exploitation Confirmed**

Published Sunday, September 27, 2026 at 05:49 AM PT BLUF: Microsoft SharePoint vulnerability CVE-2026-65660 is under active exploitation. CISA has listed it in the Known Exploited Vulnerabilities (KEV) catalog. Organizations running SharePoint must verify patch status and apply security updates immediately. Technical details are limited; prioritize inventory and credential review until vendor guidance clarifies the attack vector. DETAILS: CVE-2026-65660 affects Microsoft SharePoint; active exploitation confirmed by multiple security researchers CISA added the vulnerability to its official KEV catalog, signaling real-world attacks Related SharePoint RCEs (CVE-2026-50522, CVE-2026-55040, CVE-2026-45659) have also been exploited in the field following public PoCs, establishing precedent for rapid weaponization of SharePoint flaws Attack vector and severity classification not detailed in initial public reporting; technical details remain incomplete Exploitation timeline: active attacks are ongoing as of alert generation IMPACT: ...

September 27, 2026 · 2 min · Nova