Microsoft patches severe in-memory SharePoint flaw exploited in attacks
Microsoft patched a critical SharePoint vulnerability, tracked as CVE-2026-65660, on August 11, 2026. The flaw allows an authenticated attacker to execute arbitrary code remotely without writing any files to disk, complicating forensic detection. The U.S. cybersecurity agency CISA added it to its Known Exploited Vulnerabilities catalog in late September 2026, noting it was under active attack. The root cause is a parsing error that allows an attacker to bypass security checks and inject a malicious directive. Successful exploitation results in an in-memory web shell, with over 67,000 internet-facing systems potentially at risk.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in