VULNERABILITY INTELLIGENCE
CVE-2026-65660
CVSS score6.5 MEDIUM
EPSS probability2.10%
CISA KEVKnown exploited vulnerability
Published2026-08-11
Last modified2026-09-26
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Known Exploited Vulnerability
Microsoft SharePoint Code Injection Vulnerability
Vendor / product: Microsoft / SharePoint
Description
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Weakness classification
- CWE-94: Improper Control of Generation of Code ('Code Injection')
Primary references
- secure@microsoft.com — Patch, Vendor Advisory
- 134c704f-9b21-4f2e-91b3-4a467353bcc0 — Third Party Advisory
- 134c704f-9b21-4f2e-91b3-4a467353bcc0 — US Government Resource