CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Published Aug 11, 2026
- CVSS 8.8 high
- 2.1% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders SecurityWeek ·
- Google: AI Is Changing the Pace and Profile of Vulnerability Discovery SecurityWeek ·
- Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks SecurityWeek ·
- Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit SecurityWeek ·
- High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL SecurityWeek ·
- New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks SecurityWeek ·
- Pentagon Personnel Agency Data Breach Impacts 3 Million People SecurityWeek ·
- OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training SecurityWeek ·
- Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ SecurityWeek ·
- Call for Presentations Open for 2026 CISO Forum Virtual Summit SecurityWeek ·