Microsoft has acknowledged a severe remote code execution vulnerability in on-premises SharePoint Server, allowing an authenticated, low-privileged attacker to run arbitrary code over the network without user interaction This article explores vulnerability premises sharepoint. . Due to the sensitive nature of SharePoint servers and their powerful service identities, successful exploitation could provide attackers with a foothold for credential theft, lateral movement, data exfiltration, and persistent access across environments.

Because embedded quotation marks are not safely escaped, a malicious value can alter the reconstructed directive conceptually similar to an injection flaw, introducing another directive after the safety check but before ASP.NET parses the control. However, the researcher demonstrated that CVE-2026-65660 could be combined with a separate ToolPane authentication weakness to achieve pre-authentication RCE when a SharePoint deployment permits anonymous access to suitable pages.

Microsoft released fixes on August 11, 2026. The researcher also reported that the underlying technique affects SharePoint 2013, which reached end of support in April 2023, despite Microsoft’s official affected-product list covering only supported 2016, 2019, and Subscription Edition releases. Administrators should immediately patch their systems, restrict internet and anonymous access, audit low-privileged accounts, and monitor for suspicious POST requests, encoded XAML, and unusual Web Part markup.

Response teams should also examine worker-process behavior, unexpected child processes, anomalous assemblies, and volatile memory, as an in-memory implant could leave little or no webshell file on disk.