FR
live
tag

#microsoft

CVE-2026-65660 turns Microsoft’s SharePoint ‘spoofing’ flaw into remote code execution

Microsoft described CVE-2026-65660 as a CVSS 6.5 spoofing issue; researcher Dinh Ho Anh Khoa showed it is actually a code-injection flaw (CWE-94) enabling authenticated remote code execution, and CISA added it to the KEV catalog on September 25, 2026 after observed attacks. Apply the August 11 patch and audit your SharePoint 2016, 2019 and Subscription Edition servers.

June 2026 Was the Month Cybersecurity Broke Its Own Scale

Microsoft shipped its largest-ever Patch Tuesday, 24 billion stolen credentials surfaced on an exposed Elasticsearch cluster, and ransomware gangs claimed 721 new victims. Three records, one month — and none of them are a coincidence.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss