Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges
Brief
Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user interaction.
Tracked as CVE-2026-65660, the code-injection flaw carries a CVSS score of 8.8 and affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Because SharePoint servers hold sensitive documents and operate with powerful service identities, successful exploitation could provide attackers with a foothold for credential theft, lateral movement, data exfiltration, and persistent access across environments.
The vulnerability was discovered by Viettel Cyber Security researcher Dinh Ho Anh Khoa, who described it as another bypass of SharePoint’s SafeControls protection .
