HomeSecuritySharePoint vulnerability allows authenticated remote code execution

SharePoint vulnerability allows authenticated remote code execution

A vulnerability in SharePoint Server , which Microsoft initially categorized as a spoofing vulnerability with a CVSS score of 6.5, actually allows authenticated remote code execution, according to full technical details published by Viettel Cyber ​​Security researcher Dinh Ho Anh Khoa .

See also: Microsoft fixes RCE vulnerability in SharePoint

Article Image: SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The vulnerability, codenamed CVE-2026-65660, affects SharePoint Server 2016, 2019 , and Subscription Edition. Fixes are available since the August 11 security updates, and the National Vulnerability Database rates it 8.8.

Microsoft's advisory says that CVE-2026-65660 allows an authorized attacker to perform spoofing and does not attribute any impact to integrity or availability. The CVE entry published separately by Microsoft, updated on September 11, classifies the same vulnerability as a remote code execution vulnerability and states that it allows an authorized attacker to execute code. Both entries attribute CWE-94, a code injection vulnerability. Defenders who assessed CVE-2026-65660 based on the advisory saw a moderate spoofing vulnerability, not a code execution vulnerability with a near-maximum rating.

Khoa is the researcher who presented the original ToolShell exploit chain against SharePoint at Pwn2Own Berlin in May 2025. This chain was later exploited by Chinese-backed state groups and prompted urgent patches from Microsoft. The researcher has since disclosed several other SharePoint vulnerabilities, including CVE-2026-55040, an authentication bypass that attackers exploited shortly after its details were made public in August.

The latest vulnerability, CVE-2026-65660, resides in the way SharePoint checks whether server-side controls are in the SafeControls, a filter that prevents dangerous classes from loading. When the ToolPane component processes the web part markup, it reconstructs the Register directives by writing attribute values ​​between double quotes without escaping the quotes within them.

See also: Microsoft: Over 1,300 SharePoint servers vulnerable to spoofing attacks

SharePoint - SecNews.gr

An attacker can insert additional instructions through the unescaped quotes, registering arbitrary .NET classes after the type check is performed but before the check is loaded.

By loading arbitrary classes, the attacker uses XamlServices.Parse() to cause code execution via deserialization. The report includes a functional webshell load into memory that avoids the write permission failures encountered by other deserialization methods, Khoa said.

The researcher also showed that the flaw can be combined with a separate, already patched authentication bypass to achieve remote code execution before authentication on servers configured to allow anonymous access to pages. Khoa states that the bypass was fixed in a June 9th update, and servers that applied the fix are not exposed in the pre-authentication path.

No exploits of CVE-2026-65660 have been reported in the wild, and the flaw is not on the CISA list of Known Exploited Vulnerabilities. Microsoft's advisory rates the exploit as unlikely, although the full exploit markup is now public. Khoa says he has used the exploit in penetration testing.

The August 11 update fixes the flaw and disables the vulnerable feature by default, according to the researcher.

See also: SharePoint RCE vulnerability allows domain compromise

CVE-2026-55040 critical vulnerability Microsoft SharePoint authentication bypass PoC

Khoa also indicates that the vulnerability affects SharePoint 2013, although Microsoft's advisory only mentions versions 2016, 2019, and the Subscription Edition. SharePoint 2013 is no longer supported in April 2023 and does not receive security updates.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS