CVE Tools

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker NewsBy The Hacker News

PoC publicSharePoint Server

Our summary

Technical details and a public proof of concept show that CVE-2026-65660 in Microsoft SharePoint Server can enable authenticated remote code execution, despite initially being described as a spoofing issue. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition, where crafted web-part markup can bypass SafeControls checks and load arbitrary .NET classes. Microsoft patched the issue in its August 11 security updates; no in-the-wild exploitation has been reported.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store