# Public research shows SharePoint flaw permits authenticated code execution

_Published Tuesday, September 22, 2026 at 9:07 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![Public research shows SharePoint flaw permits authenticated code execution — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu0R8P6iyk50vNReEGl0FkwYoFPk5n2fkVC3_3Mf2J5SaQ7yFIHbA3xuQpCATCQ9Y5Ie2ysz9EVaDb_vR5Bbnp209w28bSDK2Rqggotv4NPQbFB5LX4SUT4eztA-6939clsV9QQ41MHwIl8MFSzaJwyFFeBusztZ9H7oZhiUOlFYrL8BQh6hXWegn39uU/s1700-nu-rw-lo-l85-e365/ms-rce.jpg)

A SharePoint Server vulnerability Microsoft initially rated as a moderate spoofing issue can let an authenticated attacker execute code, according to technical details and working exploit markup published by Viettel Cyber Security researcher Dinh Ho Anh Khoa. CVE-2026-65660 affects SharePoint Server 2016, 2019 and Subscription Edition.

The flaw lets an attacker bypass a filter for server-side controls by injecting directives through unescaped quotation marks, then load arbitrary .NET classes and trigger code execution. Microsoft issued a patch on August 11, and the exploit can reach unauthenticated servers only when combined with a separate bypass already fixed on June 9. No exploitation in the wild has been reported.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html)

---
Canonical: https://techandbusiness.org/newswire/xz1T5jFD_RoEJfQ01C_QYn
Published: 2026-09-22T13:07:44.468Z
Story chronology: 2026-09-22T11:17:41.000Z
Retrieved: 2026-09-22T14:58:28.272Z
Publisher: Tech & Business (techandbusiness.org)
