Defensive self-check · CISA KEV 2026-09-25
SharePoint CVE-2026-65660: build and admin self-check
CISA added CVE-2026-65660 on 2026-09-25. It is a code-injection issue in Microsoft SharePoint. Check the farm you administer. This page does not include exploit steps.
Check these three things
- Build number. In Central Administration open System Settings → Manage servers in this farm and compare the build with the fixed build in the Microsoft advisory.
- Site-collection administrators. Review each site collection's administrators and remove accounts your organization does not recognize.
- Solutions. Open Farm Solutions and look for packages deployed after the advisory date that your change record does not explain.
What to do
Install the Microsoft update for the affected build, then repeat the administrator and solution review. If the farm cannot be patched immediately, restrict access to the SharePoint web applications at the firewall until the update is in place.
Vendor record: CISA KEV catalog, entry CVE-2026-65660.