New Code Injection Vulnerability for Microsoft Sharepoint

The Canadian Centre for Cyber Security has released an advisory regarding a vulnerability for versions of Microsoft SharePoint Server.

The vulnerability may potentially enable:

  • An authorized attacker to execute code over a network (CVE-2026-65660).

To prevent exploitation of this vulnerability, ensure that your systems are updated to the following build numbers or greater:

  • SharePoint Enterprise Server 2016: 16.0.5565.1001

  • SharePoint Server 2019: 16.0.10417.20198

  • SharePoint Server Subscription Edition: 16.0.19725.20522

Additionally, see the below table for the SharePoint versions this CVE will affect:

CVE SharePoint Enterprise Server 2016 SharePoint Server 2019 SharePoint Server Subscription Edition
CVE-2026-65660 Versions prior to 16.0.5565.1001 Versions prior to 16.0.10417.20198 Versions prior to 16.0.19725.20522

For more information on security updates, please see Microsoft's CVE info page: CVE-2026-65660

It is recommended that you install these patches as soon as possible if you are running an affected version. Fixed software is available via Microsoft update or can be downloaded directly from Microsoft. You should also regularly audit your user permissions to ensure you don't have more than the number of users with contributor or higher permissions needed to minimize the attack surface of these exploits.

General guidance for protecting your environment is available from the Canadian Centre for Cyber Security.

Please also keep in mind that Microsoft SharePoint Enterprise Server 2016 and Server 2019 have reached their end of life dates as of July 15, 2026. It is strongly urged to migrate to a newer and supported version.