Microsoft SharePoint flaw added to US 'actively exploited' list — here's what we actually know

CISA says CVE-2026-65660 is being exploited in the wild, but the public record so far is thin on how, by whom, and against which SharePoint setups.

Pink and silver padlock on black computer keyboard
Photo · FlyD / Unsplash

A vulnerability in Microsoft SharePoint has been added to the US government’s list of security flaws known to be actively exploited, with federal agencies given just three days to sort it out. The bug, tracked as CVE-2026-65660, went onto the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalogue on 25 September 2026, with a fix required by 28 September.

The headline claim worth checking here is a simple one: is this actually being exploited, or just theoretically exploitable? CISA’s listing states plainly that exploitation is “confirmed, not theoretical” — that’s a meaningfully stronger claim than most vulnerability disclosures make, and it’s the reason this one has jumped straight onto a binding US federal deadline rather than sitting in a routine patch queue.

What the bug actually does

Here’s the catch: neither CISA’s catalogue entry nor the linked NVD record, as published, spells out the technical mechanics of the flaw — no confirmation of whether it’s a remote code execution issue, an authentication bypass, or something else, and no CVSS severity score is given in the material we’ve seen. What is stated is the essentials: it affects Microsoft SharePoint, it’s been assigned CVE-2026-65660, and CISA considers it exploited in real attacks. Whether ransomware crews are involved is listed by CISA itself as “Unknown” — so treat any dramatic framing of this as a ransomware story with caution until that changes.

So who is actually at risk

This is an enterprise story, not a consumer one. SharePoint is Microsoft’s collaboration and document-management platform, typically deployed by organisations either on their own servers (SharePoint Server) or via Microsoft 365 in the cloud — it isn’t something that sits on home PCs or personal devices. If you don’t administer a SharePoint deployment for a business, school, or public body, this vulnerability has no direct bearing on you.

The binding 28 September deadline applies specifically to US federal civilian agencies, under CISA’s directive powers — it does not compel anyone in the UK, and it doesn’t automatically mean private companies elsewhere are required to act by that date. That said, KEV listings are widely treated across the industry as a strong practical signal: if CISA says a bug is being actively used against real targets, IT teams everywhere tend to move quickly regardless of jurisdiction, because attackers rarely respect borders.

What to do about it

CISA’s own guidance is to apply mitigations “in accordance with vendor instructions” — in plain terms, check Microsoft’s advisory for CVE-2026-65660 and apply whatever patch or workaround it specifies, rather than waiting for further prompting. Anyone running SharePoint Server on-premises, in particular, should treat this as a priority patching job. If your organisation uses IT support or a managed service provider, this is a reasonable moment to ask them directly whether your SharePoint instances have been checked against this CVE.

The takeaway

This is a genuine, confirmed-active vulnerability in a widely used enterprise product, and organisations running SharePoint should patch promptly rather than assume it’s someone else’s problem. But the public detail remains sparse — no confirmed ransomware link, no published severity score, and no breakdown yet of how widespread the exploitation actually is. Worth acting on if you’re an admin; not a reason for the average reader to lose any sleep.

Sources