Spots

SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites…

Article Title: CVE-2026-65660: Previdian observes two-stage SharePoint exploitation attempts Publication Date: September 24, 2026 Original Update Date: September 25, 2026 Original Source: Previdian

Related Malware, Attack Groups, CVEs, and Products: sphealth.aspx

Related Malware, Attack Groups, CVEs, and Products: sphealth.aspx, SdLoader, CVE-2026-65660, Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

Severity: Critical (Active exploitation confirmed and added to

Severity: Critical (Active exploitation confirmed and added to CISA KEV. While the vulnerability itself is a high-severity RCE requiring low-privileged authentication, it can become an unauthenticated RCE when chained with a separate delivery vector on anonymously accessible sites.)

Revision Notes: Separated the anonymous delivery vector fix

Revision Notes: Separated the anonymous delivery vector fix from the main CVE patch, clarified product-specific patching boundaries, clarified that the observations comprised 12 requests, detailed payload analysis and execution success, and specified IIS logging conditions. Aligned active exploitation evidence with official CISA data and updated the original update date.

Previdian observed attacks attempting to deliver XAML deserialization

Previdian observed attacks attempting to deliver XAML deserialization payloads and create web shells without authentication by chaining SharePoint type-checking bypass CVE-2026-65660 with a separate anonymous access issue. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 25.

The observed attacks attempt to compromise systems by

The observed attacks attempt to compromise systems by chaining an anonymous access vector with the vulnerability (CVE-2026-65660) using a two-stage payload. The role and observation status of each stage are detailed below. Comparison of Observed Two-Stage Payloads Two-Stage Attack Chaining Anonymous Access Vector and CVE-2026-65660

Attackers send a POST request to the WebPart

Attackers send a POST request to the WebPart editing endpoint without an authentication cookie to SharePoint sites that allow anonymous viewing, passing crafted WebPart data with DisplayMode=Edit.

By routing through a separate anonymous delivery issue

By routing through a separate anonymous delivery issue (patched in June), the payload reaches the ToolPane handler, which normally requires authentication. Note that even in environments without anonymous access, attackers with valid low-privileged credentials can exploit CVE-2026-65660 independently.

The first-stage payload (ActivitySurrogateDisableTypeCheck) attempts to disable…

The first-stage payload (ActivitySurrogateDisableTypeCheck) attempts to disable type checking. The observed payload uses a serialization format distinct from public research, and it remains unconfirmed whether constraints were successfully bypassed in real environments.

The second-stage payload (ActivitySurrogate gadget, encrypted DLL, and

The second-stage payload (ActivitySurrogate gadget, encrypted DLL, and SdLoader) attempts to decrypt the DLL and load it into memory using Assembly.Load(byte[]). This is based on static functional analysis of the payload and does not imply successful actual execution.

News

SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access

Article Title: CVE-2026-65660: Previdian observes two-stage SharePoint exploitation attempts Publication Date: September 24, 2026 Original Update Date: September 25, 2026 Original Source: Previdian

@spots #dev
Source: Dev.to
See more like this