CyberPrism Logo

CyberPrism.App

Illuminating vulnerabilities from every angle

Back to resources

Vulnerability Management

SharePoint CVE-2026-65660: Exposure and Response Checklist

Respond to active SharePoint CVE-2026-65660 exploitation: identify exposed servers, verify security updates, investigate suspicious activity, and track closure.

Updated 2026-09-28 · 3 min read

Exposure

Check every server

Record the installed build, access paths, and accountable owner for each SharePoint server.

Remediation

Verify completion

Attach evidence of the resulting build and completed vendor update procedure.

Investigation

Define the evidence window

Record which systems and dates were reviewed, including gaps in retained logs.

Useful CyberPrism references

What should teams do about CVE-2026-65660?

Identify affected SharePoint servers, reduce unnecessary exposure, apply the relevant security updates, and investigate suspicious activity. Track update completion and compromise assessment separately.

As of September 28, 2026, the Canadian Cyber Centre's September 24 alert reports active exploitation of CVE-2026-65660, a SharePoint Server code-injection vulnerability. It warns that chaining with other vulnerabilities can enable execution before authentication on servers permitting anonymous access. [Read the alert](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).

Build an exposure record for each server

Suggested response record: server identifier, farm membership, product edition, installed build, external hostname, anonymous-access setting, and service owner. Include test and recovery environments in the inventory.

Have the network owner verify actual access paths, including proxies and publishing rules. Record when each path was checked so responders can distinguish current exposure from historical exposure.

Verify updates across the farm

Use the [Microsoft advisory](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660) to select the applicable security update and installation instructions. The Cyber Centre also recommends applying prior SharePoint security updates and reducing direct internet exposure. [Remediation guidance](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).

For each server, attach the resulting build, installation result, and confirmation that required configuration steps completed. Give failed or deferred updates an owner, temporary access restriction, and next decision time.

Review evidence of compromise

The Cyber Centre recommends reviewing SharePoint, IIS, endpoint, and authentication logs. Its investigation leads include unexpected web-part changes, suspicious IIS machine-key access, web shells, and malicious process execution. [Detection guidance](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).

Suggested investigation record: earliest known exposure, available log dates, suspicious events, and affected identities. Preserve relevant evidence and escalate credible findings through the incident-response process.

Describe a negative search precisely: which servers, time range, and event sources were checked. Missing logs leave an unresolved question about that period.

Close with evidence leadership can review

Use two closure fields: remediation verified and investigation disposition. An installed update does not establish whether exploitation occurred earlier.

A concise status note can read: Server or farm; exposure checked at; update evidence; investigation coverage; remaining gap; owner; next review. Keep unresolved evidence gaps visible when reporting remediation progress.

FAQ

Does CVE-2026-65660 require authentication?

The Cyber Centre describes the vulnerability itself as permitting authenticated code execution. It also warns that a chain involving other vulnerabilities can enable pre-authentication execution where anonymous access is allowed. [Technical context](https://www.cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660).

Can we close the incident after patching SharePoint?

Close the remediation task once the update is verified. Close the incident assessment only after responders document findings, investigation coverage, and remaining uncertainty; patch status alone does not resolve historical compromise.

Try CyberPrism

Track CVEs, threat actors, breaches, ransomware activity, and vendor exposure from a mobile-first cybersecurity app.