Verified vulnerability record
CVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability · affected before 16.0.5565.1001
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Sensor telemetry
20 attempts · 1 sensor
First-party observations recorded across 5 attacker IPs.
Evidence
Active exploitation observed
Previdian independently recorded this as exploited after first seeing it in honeypot sensors.
Actionable artifact
Enrichment available
CVSS, EPSS, and related context help prioritize remediation.
Evidence, telemetry, and action stay attached to the CVE.
Browse exploited vulnerabilities →