Skip to content
Bellator Cyber Guard
News8 min readStandard

SharePoint Bug CVE-2026-65660 Added to CISA's KEV List

CISA added the actively exploited SharePoint flaw CVE-2026-65660 to its KEV catalog with a September 28, 2026 federal deadline. What to do now.

By Bellator Cyber Guard Security Team
SharePoint Bug CVE-2026-65660 Added to CISA's KEV List - sharepoint critical vulnerability active exploitation 2026 update 2026

CISA Sets September 28 Deadline for Actively Exploited SharePoint Flaw

A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is being exploited in active attacks, and the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. federal agency responsible for coordinating national cybersecurity defense, has added it to its Known Exploited Vulnerabilities (KEV) catalog. The KEV catalog is CISA's public list of software flaws it has confirmed are being used in real-world attacks, and federal civilian executive branch agencies were given a remediation deadline of September 28, 2026, to patch it.

The description provided for this story does not include the vulnerability's technical class, such as whether it allows remote code execution, privilege escalation, or authentication bypass, nor does it confirm which SharePoint deployment types are affected. Organizations running SharePoint should check Microsoft's Security Update Guide directly for the CVE-2026-65660 entry, which is the authoritative source for affected versions, the associated knowledge base article, and available fixes.

SharePoint is used across organizations of every size as a document management and collaboration platform, deployed either as SharePoint Server on internal infrastructure or as SharePoint Online within Microsoft 365. Both deployment models have been repeated targets for attackers in recent years because a single exploited server can expose large volumes of internal files and, in on-premises setups, can sometimes serve as a foothold into the wider network.

Key Takeaway

A CISA KEV listing means exploitation is already happening, not theoretical. The September 28, 2026 deadline is a legal requirement for federal agencies only, but Bellator Cyber Guard recommends every organization running SharePoint, whether on-premises or online, treat this as an immediate patch priority rather than waiting on a compliance calendar.

Why a KEV Catalog Listing Changes the Calculus

CISA does not add every high-severity CVE to the KEV catalog. According to CISA, a vulnerability is only added to the Known Exploited Vulnerabilities catalog when there is evidence it is being actively used in attacks, which makes the listing a stronger prioritization signal than a CVSS score alone. The federal remediation deadline traces back to Binding Operational Directive 22-01, which legally requires Federal Civilian Executive Branch (FCEB) agencies to patch or mitigate cataloged vulnerabilities by the assigned date.

Private-sector organizations, including healthcare practices, tax and accounting firms, and small businesses, are not bound by BOD 22-01. Attackers running mass exploitation campaigns generally do not distinguish between federal and private targets, and historically, once a CVE reaches the KEV catalog, opportunistic scanning against internet-facing SharePoint servers tends to increase quickly. It remains unclear from available reporting whether CVE-2026-65660 affects SharePoint Server, SharePoint Online, or both, so confirming exposure against Microsoft's own advisory is the necessary first step before assuming risk either way.

What Healthcare Practices, Tax Firms, and Small Businesses Should Do Now

The practical response to a KEV-listed vulnerability is the same regardless of sector, but the compliance stakes differ for regulated practices. Bellator Cyber Guard recommends the following steps this week:

Inventory your SharePoint footprint. Identify every SharePoint Server instance on internal or DMZ infrastructure, and separately confirm the patch status of any Microsoft 365 tenant using SharePoint Online.

Check the official advisory. Look up CVE-2026-65660 in Microsoft's Security Update Guide for the exact affected versions, the relevant KB number, and whether a cumulative update or out-of-band patch applies.

Patch now, not by the deadline. September 28, 2026 is a federal enforcement date, not a safe target for private organizations. Apply the update as soon as it is validated in your environment.

Reduce exposure if patching is delayed. Restrict external network access to SharePoint Server front-ends, enforce multifactor authentication on any accounts with SharePoint access, and review authentication and file-access logs for unusual activity since the vulnerability's disclosure.

Document remediation for regulated practices. Healthcare covered entities under HIPAA and tax preparers following IRS Publication 4557 guidance are both expected to address known-exploited vulnerabilities in a timely manner as part of a documented security risk analysis. Recording when the patch was identified, tested, and applied supports that requirement if it is ever reviewed.

Consider a compromise check for long-exposed servers. If a SharePoint Server instance has been internet-facing and unpatched for an extended period before this KEV listing, a focused log and endpoint review can help rule out prior compromise rather than assuming the patch alone resolves the risk.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Incident response & NIST

Build a response process that helps people detect, contain, recover, and improve when something goes wrong.

Learn first. Decide when you are ready.

Keep learning, or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.