SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
- ID
- 27203
- Status
- summarized
- Published
- 22 Sep 2026, 7:17 PM
- Fetched
- 22 Sep 2026, 8:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 22 Sep 2026, 8:21 PM
- Tags
- Audience
- developerssaas_founders
What happened
Microsoft initially classified CVE-2026-65660 as a spoofing flaw (CVSS 6.5) but it is actually authenticated remote code execution (CVSS 8.8) affecting SharePoint Server 2016, 2019, and Subscription Edition. The flaw exploits unescaped quotes in Register directives within the ToolPane component, allowing arbitrary .NET class loading and code execution via XamlServices.Parse() deserialization. Patches have been available since August 11, but defenders who triaged based on Microsoft's advisory may have deprioritized patching a 'moderate spoofing' issue.
Why it matters
If your organization runs on-prem SharePoint Server (not SharePoint Online/M365), verify that August 11 patches are applied—this was likely deprioritized due to Microsoft's misleading spoofing classification. The broader lesson for builders: don't trust vendor CVSS labels alone; cross-check the separate CVE record, which in this case correctly flagged RCE while the advisory did not.
Discussion angle
How vendor misclassification of severity can cause patching delays—what secondary sources or CVE records should defenders check when a vendor advisory seems to understate impact?