
Intro
Active in-the-wild exploitation has been observed targeting Microsoft SharePoint Server via CVE-2026-65660, a high-severity code injection vulnerability that allows authenticated attackers with low-level privileges to achieve remote code execution. Originally disclosed during the August 2026 Patch Tuesday cycle, threat actors began operationalizing public technical details in late September 2026, dropping web shell backdoors on exposed enterprise servers and prompting immediate CISA Known Exploited Vulnerabilities (KEV) catalog inclusion.
CVE Context
– Products & versions affected:
Microsoft SharePoint Enterprise Server 2016 (prior to build 16.0.5565.1001)
Microsoft SharePoint Server 2019 (prior to build 16.0.10417.20198)
Microsoft SharePoint Server Subscription Edition (prior to build 16.0.19725.20522)
– Disclosure timeline:
August 11, 2026: Coordinated disclosure and security update released by Microsoft.
Late September 2026: Viettel Security published technical analysis; threat actors weaponized proof-of-concept vectors.
September 24-25, 2026: In-the-wild honeypot exploitation and web shell deployments recorded.
September 25, 2026: Added to CISA KEV catalog under federal Binding Operational Directive enforcement.
– Attack vector, auth level, impact:
Network-accessible, authenticated (low privilege), high confidentiality, integrity, and availability impact.
CVSS Metric Breakdown (v3.1) - CVE-2026-65660 (SharePoint Code Injection RCE)Attack Vector (AV): Network (N)Attack Complexity (AC): Low (L)Privileges Required (PR): Low (L)User Interaction (UI): None (N)Confidentiality Impact (VC): High (H)Integrity Impact (VI): High (H)Availability Impact (VA): High (H)Scope Changed (SC): Unchanged (U)Safety Impact (SI): Not ApplicableAutomation (SA): Not ApplicableExploit Maturity: Functional / Proof of Concept in the WildBase Score: 8.8 (High)
– Exploit tools, payloads observed, confirmed victims, global exposure count if known: Threat actors have been observed executing automated two-stage payload drops delivering ASPX/ASHX web shell backdoors directly to w3wp worker processes. Shodan and Censys telemetry reveal thousands of internet-exposed on-premises SharePoint endpoints worldwide.
EPSS Scoring
EPSS Probability: 0.02101
EPSS Percentile: 0.81009
The Exploit Prediction Scoring System (EPSS) rating places CVE-2026-65660 at an estimated 2.10% probability of active exploitation in the wild over the next 30 days, ranking it higher than 81.01% of all scored vulnerabilities globally. While a 2.10% nominal probability appears moderate on surface review, placing above the 81st percentile combined with confirmed CISA KEV status establishes this as an immediate operational priority for patch verification and forensic validation.
Exploitation Detail
– Step-by-step breakdown:
1. An attacker establishes an authenticated session using compromised low-privilege domain or SharePoint member credentials.
2. The attacker crafts a targeted HTTP POST request toward an internal SharePoint processing endpoint handling serialized server-side data models.
3. Flawed type-validation routines fail to properly sanitize dynamic object deserialization and parameter injection.
4. The injected payload invokes arbitrary server-side methods within the context of the IIS worker process (w3wp.exe).
– Where it lives: Type-checking and input validation parsers within core SharePoint server assemblies handling serialized application state and dynamic page compilation.
POST /_vti_bin/client.svc/ProcessQuery HTTP/1.1 Host: sharepoint.target-domain.local Authorization: NTLM TlRMTVNTUAABAAA... Content-Type: text/xml; charset=utf-8 X-RequestDigest: 0x8A...<Request AddExpandoFieldTypeSuffix="true" SchemaVersion="15.0.0.0" LibraryVersion="16.0.0.0" xmlns="http://schemas.microsoft.com/sharepoint/clientquery/2009">
<Actions>
<ObjectPath Id="2" ObjectPathId="1" />
<Method Name="CompileMarkup" Id="3" ObjectPathId="1">
<Parameters>
<Parameter Type="String"><![CDATA[<%@ Page Language="C#" %><% System.Diagnostics.Process.Start("cmd.exe","/c whoami > C:\inetpub\wwwroot\out.txt"); %>]]></Parameter>
</Parameters>
</Method>
</Actions>
<ObjectPaths>
<StaticMethod Id="1" TypeId="{F6B431D0-179B-4D24-8D29-566A1F7A2DC1}" Name="CreateInstance" />
</ObjectPaths>
</Request>
Attacker Behavior Snapshot
– What the attacker sends: Malformed serialized XML/JSON POST requests containing embedded compilation directives or type-check override parameters directed at SharePoint client endpoints (_vti_bin/client.svc, /_layouts/15/).
– What the system does: The underlying application pool worker (w3wp.exe) fails to enforce strict type checking, deserializes the untrusted object, and compiles or executes the embedded payload using the privileges of the SharePoint service account (often local SYSTEM or highly privileged domain accounts).
– What leaks back: Detailed CLR stack traces, internal netBIOS/FQDN machine paths, ASP.NET session tokens, and output from injected commands rendered directly in HTTP 200/500 response bodies.
Why This Matters
This vulnerability highlights how legacy configurations become high-value targets. On-premises collaboration suites bridge internal document repositories and Active Directory, turning a single compromised workstation or low-tier service account into a pipeline for enterprise-wide compromise.
Exploitation results in:
- Full command execution on web servers
- Untraceable persistence via web shells
- Rapid lateral movement if not detected early
MITRE ATT&CK Mapping
Initial Access: T1190 – Exploit Public-Facing Application
Execution: T1059.003 – Command Shell
Persistence: T1505.003 – Server Software Component
Detection Rules
YARA Rule (Memory/Doc/PCAP)
rule APT_Webshell_SharePoint_CVE_2026_65660 { meta: description = "Detects web shells dropped via CVE-2026-65660 SharePoint exploitation" author = "Cyber Pulse Threat Research" date = "2026-09-30" severity = "Critical" strings: $str1 = "<%@ Page Language=" ascii nocase $str2 = "Process.Start" ascii wide $str3 = "client.svc/ProcessQuery" ascii wide $str4 = "SPPageContentManager" ascii wide $magic = { 3C 25 40 20 } condition: $magic at 0 and ($str1 and ($str2 or ($str3 and $str4)))}
Suricata or Zeek (Network)
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible Microsoft SharePoint CVE-2026-65660 Code Injection"; flow:established,to_server; content:"POST"; http_method; content:"/client.svc/ProcessQuery"; http_uri; content:"CompileMarkup"; nocase; content:"System.Diagnostics.Process"; nocase; classtype:attempted-admin; sid:2026656; rev:1;)
Sigma Rule (SIEM/EDR)
title: SharePoint w3wp.exe Spawning Interactive Command Shellid: b5e4128f-7c19-4a48-a0d3-34e857829a24status: experimentaldescription: Detects Microsoft SharePoint IIS worker process spawning command interpreters or script hosts.references: - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660author: Cyber Pulsedate: 2026-09-30logsource: category: process_creation product: windowsdetection: selection: ParentImage|endswith: '\w3wp.exe' Image|endswith: - '\cmd.exe' - '\powershell.exe' - '\pwsh.exe' - '\wscript.exe' - '\cscript.exe' - '\certutil.exe' condition: selectionfalsepositives: - Rare administrative deployment scripts run through web consoles (verify parent command line)level: criticaltags: - attack.execution - attack.t1059.003 - attack.initial_access - attack.t1190
Detection Strategies
Network Detection:
- Look for suspicious HTTP POST requests to php-cgi.exe
- Detect URL-encoded payloads with %0a, &, or |
- Flag legacy user-agents such as MSIE 6.0 or default China Chopper signatures
Endpoint Detection:
- php-cgi.exe spawning cmd.exe or powershell.exe
- Unexpected script file creation in C:\inetpub\wwwroot\
- Look for command-line logging or scheduled task creation tied to web server processes
Splunk Query
index=main sourcetype="WinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode=1ParentImage="*\\w3wp.exe" Image IN ("*\\cmd.exe", "*\\powershell.exe", "*\\whoami.exe", "*\\net.exe")| stats count min(_time) as first_seen max(_time) as last_seen by host, user, ParentCommandLine, CommandLine| convert ctime(first_seen) ctime(last_seen)| sort - count
SOC Detection Strategy
– Triage levels, log sources, alert logic:
P1 Critical: Any alert indicating w3wp.exe spawning interactive shells (cmd.exe, powershell.exe) or reconnaissance utilities (whoami.exe, nltest.exe) on SharePoint tier servers.
P2 High: Network detection of anomalous POST requests to client.svc containing serialized code compilation markup.
Log Sources Required: Windows Event ID 4688 with full command-line arguments, Sysmon Event ID 1 (Process Creation), Sysmon Event ID 11 (File Create), IIS W3C Logs, and WAF HTTP telemetry.
– How to tune and escalate:
Correlate endpoint process execution timestamps directly against IIS CS-URI-Stem logs. If an unexpected binary execution occurs within milliseconds of a client.svc POST request from an external IP, escalate immediately to full containment and incident response.
– What real-world alerts might look like:
“EDR Alert: Anomalous Parent-Child Execution – w3wp.exe spawned powershell.exe with base64 encoded arguments on SHAREPOINT01.”
Tools & Techniques
Tool | Usage
Sysmon | Detect parent-child anomalies
Velociraptor | Endpoint hunting for shell commands
Zeek | HTTP signature logging and anomaly detection
Sigma/YARA | Create detection rules for known web shell patterns
Mitigation & Response
– Patch info: Apply the official Microsoft August 2026 security updates for SharePoint (KB5002905 and related cumulative rollups for Enterprise 2016, 2019, and Subscription Edition).
– Temporary mitigations (GPOs, ACLs, WAF): Restrict internal access to SharePoint administrative endpoints; place public-facing SharePoint farms behind a reverse proxy enforcing strict inspection of POST requests to /_vti_bin/ and /_layouts/ paths.
– Config changes, credential rotation, MFA enforcement, registry edits:
Enforce Multi-Factor Authentication across all accounts with network access to SharePoint to limit low-privilege authentication vector abuse.
– Use a WAF to block suspicious characters in user input (e.g., %0a, &, |)
– Disable legacy components (e.g., PHP-CGI) if not needed
– Monitor for lateral movement post-compromise
Incident Response Snippets
– Log queries (grep, Splunk, KQL):
KQL:
DeviceProcessEvents
| where InitiatingProcessFileName =~ “w3wp.exe”
| where FileName in~ (“cmd.exe”, “powershell.exe”, “whoami.exe”, “net.exe”)
| project Timestamp, DeviceName, ActionType, FileName, ProcessCommandLine, InitiatingProcessCommandLine
– IR questions to ask:
1. Which accounts authenticated against the SharePoint farm immediately prior to the observed execution?
2. Was the parent process running under the local Network Service, Local System, or a delegated Active Directory service account?
3. Did the child process establish secondary outbound network connections to external IP addresses?
– Cleanup and movement checks:
Inspect C:\inetpub\wwwroot\ and SharePoint hive directories (C:\Program Files\Common Files\microsoft shared\Web Server Extensions\) for newly dropped .aspx or .ashx files created within the incident window.
Suggested Reading & External References
– Official advisories:
Microsoft Security Update Guide: CVE-2026-65660
CISA Known Exploited Vulnerabilities Catalog
– Trusted writeups:
SecurityWeek: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
– Related CVEs or historic cases:
Related enterprise code injection flaws include CVE-2023-29357 (SharePoint Authentication Bypass) and CVE-2023-24955 (SharePoint RCE chain).
Final Thoughts
– One-sentence summary of exploit path: Threat actors leverage low-privilege authenticated access to inject code into unvalidated SharePoint server-side compilation endpoints, achieving SYSTEM-level execution via w3wp worker processes.
– Most effective action to take now: Verify deployment of Microsoft cumulative updates across all on-premises SharePoint tiers and hunt for anomalous w3wp child processes across EDR logs.
– Reminder that detection is field work.
Published: September 30, 2026
Leave a comment