Vulnerability Management
SharePoint CVE-2026-65660: Exposure and Response Checklist
Respond to active SharePoint CVE-2026-65660 exploitation: identify exposed servers, verify security updates, investigate suspicious activity, and track closure.
Updated 2026-09-28 · 3 min read
Exposure
Check every server
Record the installed build, access paths, and accountable owner for each SharePoint server.
Remediation
Verify completion
Attach evidence of the resulting build and completed vendor update procedure.
Investigation
Define the evidence window
Record which systems and dates were reviewed, including gaps in retained logs.
Useful CyberPrism references
Canadian Cyber Centre SharePoint Alert
September 24, 2026 alert describing exploitation, affected products, and defensive actions.
Microsoft CVE-2026-65660 Advisory
Vendor reference for product-specific security update information.
CyberPrism RIPD Framework
Explore a framework for discussing threat context and defensive priorities.
Vulnerability Trends
Review broader vulnerability activity alongside this response.
What should teams do about CVE-2026-65660?
Identify affected SharePoint servers, reduce unnecessary exposure, apply the relevant security updates, and investigate suspicious activity. Track update completion and compromise assessment separately.
As of September 28, 2026, the Canadian Cyber Centre's September 24 alert reports active exploitation of CVE-2026-65660, a SharePoint Server code-injection vulnerability. It warns that chaining with other vulnerabilities can enable execution before authentication on servers permitting anonymous access. [Read the alert](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).
Build an exposure record for each server
Suggested response record: server identifier, farm membership, product edition, installed build, external hostname, anonymous-access setting, and service owner. Include test and recovery environments in the inventory.
Have the network owner verify actual access paths, including proxies and publishing rules. Record when each path was checked so responders can distinguish current exposure from historical exposure.
Verify updates across the farm
Use the [Microsoft advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660) to select the applicable security update and installation instructions. The Cyber Centre also recommends applying prior SharePoint security updates and reducing direct internet exposure. [Remediation guidance](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).
For each server, attach the resulting build, installation result, and confirmation that required configuration steps completed. Give failed or deferred updates an owner, temporary access restriction, and next decision time.
Review evidence of compromise
The Cyber Centre recommends reviewing SharePoint, IIS, endpoint, and authentication logs. Its investigation leads include unexpected web-part changes, suspicious IIS machine-key access, web shells, and malicious process execution. [Detection guidance](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).
Suggested investigation record: earliest known exposure, available log dates, suspicious events, and affected identities. Preserve relevant evidence and escalate credible findings through the incident-response process.
Describe a negative search precisely: which servers, time range, and event sources were checked. Missing logs leave an unresolved question about that period.
Close with evidence leadership can review
Use two closure fields: remediation verified and investigation disposition. An installed update does not establish whether exploitation occurred earlier.
A concise status note can read: Server or farm; exposure checked at; update evidence; investigation coverage; remaining gap; owner; next review. Keep unresolved evidence gaps visible when reporting remediation progress.
FAQ
Does CVE-2026-65660 require authentication?
The Cyber Centre describes the vulnerability itself as permitting authenticated code execution. It also warns that a chain involving other vulnerabilities can enable pre-authentication execution where anonymous access is allowed. [Technical context](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).
Can we close the incident after patching SharePoint?
Close the remediation task once the update is verified. Close the incident assessment only after responders document findings, investigation coverage, and remaining uncertainty; patch status alone does not resolve historical compromise.
Try CyberPrism
Track CVEs, threat actors, breaches, ransomware activity, and vendor exposure from a mobile-first cybersecurity app.