Skip to content

CISA Adds CVE-2026-65660 to KEV: Patch Microsoft SharePoint Server Now

Two bits of news you should act on today: a Microsoft SharePoint Server vulnerability has landed in the Known Exploited Vulnerabilities catalog, and exploitation reports are circulating. If you run SharePoint on-premises, this deserves your attention now.

What happened

On September 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65660 to its KEV catalog. Open-source reports indicate the vulnerability has been exploited in the wild against SharePoint Server environments. Microsoft released a security update to address the issue, and organizations are encouraged to apply patches promptly.

For more details, see the CISA KEV Catalog and the Microsoft Update Guide.

Why it matters

Small businesses, organizations hosting SharePoint on-prem, and IT teams are at risk. Exploitation can lead to unauthorized access, data exposure, and potential lateral movement. Because KEV entries are prioritized for patching, this is a cue to treat this as a high-priority fix.

Practical steps you can take

  • Check if you operate Microsoft SharePoint Server on-premises or in a custom cloud deployment and confirm the version you’re running.
  • Apply the latest Microsoft security update that addresses CVE-2026-65660 as soon as possible, following your standard change control process.
  • Review access controls: restrict external access to SharePoint, enforce MFA for administrators, and segment networks to limit exposure.
  • Verify backups: ensure you have recent, offline backups and that you can restore promptly if needed.
  • Test the patch in a staging environment before rolling out to production, if possible.
  • Enable ongoing monitoring: watch for unusual login activity or abnormal file access patterns on SharePoint servers.

Final thought

Staying ahead of vulnerabilities means patching early, testing, and having a recovery plan. If you’re unsure how to proceed, start with your IT admin or your trusted MSP. Small steps today save bigger problems tomorrow.

Leave a Reply

Your email address will not be published. Required fields are marked *