One SharePoint Type Check Stood Between a Web Request and an In-Memory Shell
Update, 28 September 2026: Microsoft says it had reliable evidence by 25 September of attacks exploiting CVE-2026-65660. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on the same date, with a 28 September remediation deadline for covered US federal civilian agencies. Its entry also calls for applicable forensic triage. The federal deadline is not a universal deadline for every organisation.
Other operators should still treat this as an immediate patch-and-investigate event. Confirm the August security update or a later cumulative update is installed on every SharePoint server, then review exposed farms for signs of access before the fix. The Microsoft revision and CISA entry do not identify the attackers or quantify the attacks.
A SharePoint safety check examined one piece of markup before the application reassembled it. Researchers found that carefully split input could pass the check, become dangerous only afterwards and reach server-side code execution.
CVE-2026-65660 is a SafeControls bypass affecting on-premises SharePoint. Microsoft addressed it in the 11 August 2026 security updates. Viettel Cyber Security’s technical disclosure says the primitive can be used to build an in-memory web shell, and can be combined with another path to reach code execution without authentication in some configurations.
The pre-authentication claim needs a boundary
The research does not show that every SharePoint server can be compromised anonymously. The demonstrated route relies on a page derived from SharePoint’s WebPartPage, a usable template-parsing function and a configuration that allows anonymous access to the relevant content. Other deployments may still require an authenticated, low-privilege user.
That distinction matters operationally. Internet exposure, anonymous site access and the installed security-update level decide whether this is a remote emergency or a privilege-escalation path behind an existing account.
Why an in-memory shell changes detection
The proof of concept uses SharePoint’s design-time parsing behaviour and XAML processing to create a shell in memory. A responder looking only for a newly written ASPX file may therefore miss the most important artefact. Process behaviour, request history, loaded assemblies and memory become more valuable than a simple web-root file search.
- Identify every on-premises SharePoint 2013, 2016, 2019 and Subscription Edition farm.
- Confirm the August security updates and later cumulative updates are installed on every server in each farm.
- Review anonymous-access settings and determine which WebPart pages are reachable without authentication.
- Hunt for unusual requests to design and WebPart endpoints, particularly requests carrying complex register directives or encoded payloads.
- Examine worker-process memory and child-process activity where exploitation is suspected.
- Do not treat the absence of a dropped web-shell file as proof that the server is clean.
The researcher notes that the specific ToolPane function is disabled by default after the August fix. The wider warning is that SharePoint contains other template-parsing paths, so patching should be paired with exposure reduction and continuous monitoring rather than treated as the end of the investigation.
Microsoft has now confirmed observed attacks exploiting CVE-2026-65660. Patching closes the documented path, but it does not prove that an exposed farm was untouched before the update. Preserve relevant logs and investigate suspicious SharePoint activity where the vulnerable version was internet-accessible.
Sources
- Viettel Cyber Security technical analysis, published 22 September 2026.
- Microsoft Security Response Center entry, originally published 11 August 2026 at 07:00 PDT and revised 25 September 2026 at 07:00 PDT to confirm observed attacks.
- CISA Known Exploited Vulnerabilities catalogue, entry added 25 September 2026 with a 28 September remediation deadline for covered US federal civilian agencies. CISA provides no individual publication time.


