The record
Written from the 1 report below. Nothing here is unsourced.
- A vulnerability in Microsoft SharePoint Server identified as CVE-2026-65660 was initially mislabeled by Microsoft as a minor spoofing issue.
- Security researcher Dinh Ho Anh Khoa revealed that the flaw is actually a code-injection vulnerability permitting authenticated remote code execution.
- The issue exists within the ToolPane component's processing of web-part markup.
- Administrators should ensure that the security updates released on August 11, 2026, are fully applied to mitigate this risk.
What to watch next
- Monitoring for potential exploitation in the wild now that technical details are public.
- Checking for unpatched SharePoint 2013 instances, which remain vulnerable and unsupported.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Dinh Ho Anh Khoa
researcher
1 quote · 1 outlet
“The writeup includes a working in-memory webshell payload that avoids the registry permission failures other deserialization methods encounter”
In the article
…registering arbitrary .NET classes after the type check runs but before the control is loaded. With arbitrary class loading, the attacker uses XamlServices.Parse() to trigger code execution through deserialization. The writeup includes a working in-memory webshell payload that avoids the registry permission failures other deserialization methods encounter , Khoa said. The researcher also demonstrated that the flaw can be chained with a separate, already-patched authentication bypass to reach pre-authentication remote code execution on servers configured to allow…
Coverage1
All filed from India
Named United States · Microsoft · SharePoint · Dinh Ho Anh Khoa · National Vulnerability Database · Viettel Cyber Security
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
