[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2mkh25m7vpwvy":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6aba5936ca21c797c7e98633","sharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96","SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access","Article Title: CVE-2026-65660: Previdian observes two-stage SharePoint exploitation attempts Publication Date: September 24, 2026 Original Update Date: September 25, 2026 Original Source: Previdian","news",[10,13,18,23,28,33,38,43,48,53],{"headline":11,"body":7,"imageUrl":12,"sourceImageUrl":12},"SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites…","https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F96ysnp6qlno40avhugdh.png",{"headline":14,"body":15,"imageUrl":16,"images":17},"Related Malware, Attack Groups, CVEs, and Products: sphealth.aspx","Related Malware, Attack Groups, CVEs, and Products: sphealth.aspx, SdLoader, CVE-2026-65660, Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"Severity: Critical (Active exploitation confirmed and added to","Severity: Critical (Active exploitation confirmed and added to CISA KEV. While the vulnerability itself is a high-severity RCE requiring low-privileged authentication, it can become an unauthenticated RCE when chained with a separate delivery vector on anonymously accessible sites.)","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"Revision Notes: Separated the anonymous delivery vector fix","Revision Notes: Separated the anonymous delivery vector fix from the main CVE patch, clarified product-specific patching boundaries, clarified that the observations comprised 12 requests, detailed payload analysis and execution success, and specified IIS logging conditions. Aligned active exploitation evidence with official CISA data and updated the original update date.","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"Previdian observed attacks attempting to deliver XAML deserialization","Previdian observed attacks attempting to deliver XAML deserialization payloads and create web shells without authentication by chaining SharePoint type-checking bypass CVE-2026-65660 with a separate anonymous access issue. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 25.","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"The observed attacks attempt to compromise systems by","The observed attacks attempt to compromise systems by chaining an anonymous access vector with the vulnerability (CVE-2026-65660) using a two-stage payload. The role and observation status of each stage are detailed below. Comparison of Observed Two-Stage Payloads Two-Stage Attack Chaining Anonymous Access Vector and CVE-2026-65660","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"Attackers send a POST request to the WebPart","Attackers send a POST request to the WebPart editing endpoint without an authentication cookie to SharePoint sites that allow anonymous viewing, passing crafted WebPart data with DisplayMode=Edit.","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"By routing through a separate anonymous delivery issue","By routing through a separate anonymous delivery issue (patched in June), the payload reaches the ToolPane handler, which normally requires authentication. Note that even in environments without anonymous access, attackers with valid low-privileged credentials can exploit CVE-2026-65660 independently.","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"The first-stage payload (ActivitySurrogateDisableTypeCheck) attempts to disable…","The first-stage payload (ActivitySurrogateDisableTypeCheck) attempts to disable type checking. The observed payload uses a serialization format distinct from public research, and it remains unconfirmed whether constraints were successfully bypassed in real environments.","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"The second-stage payload (ActivitySurrogate gadget, encrypted DLL, and","The second-stage payload (ActivitySurrogate gadget, encrypted DLL, and SdLoader) attempts to decrypt the DLL and load it into memory using Assembly.Load(byte[]). This is based on static functional analysis of the payload and does not imply successful actual execution.","\u002Fapi\u002Fmedia\u002Fposts\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-att-d1291a96\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Dev.to","https:\u002F\u002Fdev.to\u002Fanoymask\u002Fsharepoint-cve-2026-65660-two-stage-web-shell-deployment-attempts-on-sites-allowing-anonymous-3fbd","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},5,0,"2026-09-28T12:10:30.284Z","local"]