AI Weekly Malaysia

Back to items Summaries

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

ID
27203
Status
summarized
Published
22 Sep 2026, 7:17 PM
Fetched
22 Sep 2026, 8:16 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.0
Created
22 Sep 2026, 8:21 PM
Tags
Audience
developerssaas_founders

What happened

Microsoft initially classified CVE-2026-65660 as a spoofing flaw (CVSS 6.5) but it is actually authenticated remote code execution (CVSS 8.8) affecting SharePoint Server 2016, 2019, and Subscription Edition. The flaw exploits unescaped quotes in Register directives within the ToolPane component, allowing arbitrary .NET class loading and code execution via XamlServices.Parse() deserialization. Patches have been available since August 11, but defenders who triaged based on Microsoft's advisory may have deprioritized patching a 'moderate spoofing' issue.

Why it matters

If your organization runs on-prem SharePoint Server (not SharePoint Online/M365), verify that August 11 patches are applied—this was likely deprioritized due to Microsoft's misleading spoofing classification. The broader lesson for builders: don't trust vendor CVSS labels alone; cross-check the separate CVE record, which in this case correctly flagged RCE while the advisory did not.

Discussion angle

How vendor misclassification of severity can cause patching delays—what secondary sources or CVE records should defenders check when a vendor advisory seems to understate impact?

Top