SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
What it means
Una vulnerabilità in SharePoint Server, inizialmente classificata come spoofing da Microsoft, consente esecuzione remota di codice (RCE) con autenticazione. La vulnerabilità, CVE-2026-65660, colpisce SharePoint Server 2016, 2019 e Subscription Edition. Patch disponibili dal 11 agosto 2026. Nessun sfruttamento segnalato in ambiente reale.
Why it matters
Per le PMI italiane, la vulnerabilità rappresenta un rischio elevato per la sicurezza dei dati e delle infrastrutture. L'accesso non autorizzato a sistemi SharePoint potrebbe portare a compromissioni di dati sensibili e danni economici significativi.
Recommended actions
- Applicare immediatamente le patch disponibili dal 11 agosto 2026
- Disattivare la funzione vulnerabile per default
- Ridurre l'esposizione di SharePoint a utenti non autorizzati
- Monitorare attività di deserializzazione XAML e web-part
- Eseguire audit di configurazione SafeControls list
- Limitare l'accesso anonimo a SharePoint
- Implementare controlli di runtime per identità
Potential operational benefits
- Riduzione della superficie esposta a attacchi remoti
- Miglioramento della rilevazione di attività maliziose
- Aumento della protezione contro vulnerabilità non patchate
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
- Source
- The Hacker News
- Publishing entity
- The Hacker News
- Entity type
- editorial osint
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 22/09/2026 13:17
- MITRE ATT&CK
- T1486, T1078
- CVE
- CVE-2026-65660
Affected products and versions
The collector will check NVD and the available official vendor advisories.