HackerFeeds

CyberSecurity News

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News
· September 22, 2026

AI summary

A vulnerability in SharePoint Server, initially thought to be a spoofing flaw, has been found to actually enable authenticated remote code execution. Microsoft initially assigned a CVSS score of 6.5 to the vulnerability. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition. A researcher from Viettel Cyber Security has published full technical details on the vulnerability, identified as CVE-2026-65660. Patches have been made available for the issue.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.