Threat Overview
On September 25, 2026, Microsoft stated it had reliable evidence of attacks exploiting CVE-2026-65660, and CISA added the flaw to the Known Exploited Vulnerabilities catalog. The vulnerability is improper control of code generation (CWE-94) in on-premises Microsoft SharePoint Server. An authenticated, low-privileged attacker can exploit it over the network without user interaction to execute code; Microsoft scores it CVSS 8.8. The advisory was initially characterized as spoofing before Microsoft clarified the remote-code-execution impact.
Affected products are SharePoint Enterprise Server 2016 before 16.0.5565.1001, SharePoint Server 2019 before 16.0.10417.20198, and SharePoint Server Subscription Edition before 16.0.19725.20522. SharePoint Online is not listed as affected. Public reporting confirms exploitation but does not identify the actor, victim count, exploit request path, payload, post-exploitation tooling, or reliable campaign IOCs. Accordingly, the hunt uses authenticated HTTP anomalies and SharePoint/IIS post-exploitation behavior rather than an invented URI or signature.
References
- Microsoft Security Response Center — CVE-2026-65660 — advisory updated September 25, 2026 with observed exploitation.
- CISA Known Exploited Vulnerabilities Catalog — added September 25, 2026.
- Canadian Centre for Cyber Security — AL26-023 — September 24, 2026.
- The Hacker News — SharePoint RCE and MikroTik RouterOS flaws actively exploited — September 26, 2026.
Impacted Systems
- Vendor/product: Microsoft SharePoint Enterprise Server 2016 x64, SharePoint Server 2019 x64, and SharePoint Server Subscription Edition x64.
- Affected builds: 2016 before 16.0.5565.1001; 2019 before 16.0.10417.20198; Subscription Edition before 16.0.19725.20522.
- Fixed builds: 16.0.5565.1001, 16.0.10417.20198, and 16.0.19725.20522 respectively, delivered in August 2026 security updates.
- Deployment: On-premises/self-managed SharePoint web front ends and farms on Windows Server/IIS.
- Prerequisite: Valid low-privileged SharePoint authentication; network access to the SharePoint web application. No user interaction is required.
- Exposure: Internet-facing SharePoint increases accessibility, but authenticated internal access is also sufficient.
- Explicitly unaffected: Microsoft 365 SharePoint Online is not identified in the vendor’s affected-product list.
Why this matters
The flaw is confirmed exploited, enables code execution on a high-value collaboration server, and affects supported on-premises editions. Because no authoritative exploit path or campaign IOC has been published, behavioral evidence from IIS, endpoint process, file, authentication, and network telemetry is necessary.
Exploitation Status
Microsoft reports reliable evidence of observed attacks as of September 25, and CISA’s KEV listing independently establishes active exploitation. The public record does not confirm exploitation scale or post-exploitation behavior. Any specific web-shell, process, or egress match in these hunts is therefore an investigative lead, not proof that CVE-2026-65660 was the entry vector.
What this hunt looks for
Authenticated POST anomalies, IIS worker child processes, script and interpreter execution, web-root writes, suspicious network egress, Windows process-creation fallback, and process-to-file or process-to-network correlation.
Required logs
Microsoft Defender for Endpoint DeviceProcessEvents, DeviceFileEvents, and DeviceNetworkEvents; W3CIISLog or equivalent IIS/WAF telemetry; and Windows Security Event 4688 with command-line auditing where endpoint telemetry is unavailable.
Hunt 1 — High-likelihood IIS worker spawning command or scripting tools
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "rundll32.exe", "regsvr32.exe", "mshta.exe", "cscript.exe", "wscript.exe", "certutil.exe", "bitsadmin.exe")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, SHA256
| order by TimeGenerated desc
Hunt 2 — Rare child processes of SharePoint/IIS workers
let baseline = DeviceProcessEvents
| where TimeGenerated between (ago(30d) .. ago(1d)) and InitiatingProcessFileName =~ "w3wp.exe"
| summarize Baseline=count() by DeviceName, FileName;
DeviceProcessEvents
| where TimeGenerated > ago(1d) and InitiatingProcessFileName =~ "w3wp.exe"
| summarize Recent=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Commands=make_set(ProcessCommandLine, 10) by DeviceName, FileName, AccountName
| join kind=leftanti baseline on DeviceName, FileName
| order by Recent desc
Hunt 3 — Executable or web-shell-capable files written under IIS/SharePoint paths
DeviceFileEvents
| where TimeGenerated > ago(30d)
| where FolderPath has_any ("\\inetpub\\wwwroot\\", "\\Microsoft Shared\\Web Server Extensions\\", "\\Web Server Extensions\\16\\TEMPLATE\\LAYOUTS\\")
| where FileName endswith ".aspx" or FileName endswith ".ashx" or FileName endswith ".asmx" or FileName endswith ".dll" or FileName endswith ".exe" or FileName endswith ".ps1"
| project TimeGenerated, DeviceName, ActionType, FolderPath, FileName, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessAccountName
| order by TimeGenerated desc
Hunt 4 — Suspicious PowerShell or encoded execution from IIS context
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName in~ ("powershell.exe", "pwsh.exe")
| where InitiatingProcessFileName =~ "w3wp.exe" or InitiatingProcessParentFileName =~ "w3wp.exe"
| where ProcessCommandLine has_any ("-enc", "-encodedcommand", "FromBase64String", "DownloadString", "Invoke-WebRequest", "IEX", "-nop", "-w hidden")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
| order by TimeGenerated desc
Hunt 5 — Unusual outbound connections initiated by IIS workers
DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName =~ "w3wp.exe"
| where ActionType == "ConnectionSuccess"
| where not(ipv4_is_private(RemoteIP))
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Connections=count(), RemotePorts=make_set(RemotePort, 20), URLs=make_set(RemoteUrl, 20) by DeviceName, RemoteIP, InitiatingProcessCommandLine, InitiatingProcessAccountName
| order by Connections desc
Hunt 6 — Authenticated POST anomalies in IIS logs without assuming an exploit URI
W3CIISLog
| where TimeGenerated > ago(30d)
| extend Method=tostring(column_ifexists("csMethod", "")), UriStem=tostring(column_ifexists("csUriStem", "")), User=tostring(column_ifexists("csUserName", "")), ClientIP=tostring(column_ifexists("cIP", "")), Status=toint(column_ifexists("scStatus", 0)), BytesSent=tolong(column_ifexists("scBytes", 0)), Server=tostring(column_ifexists("Computer", ""))
| where Method =~ "POST" and User !in ("", "-")
| summarize Requests=count(), URIs=dcount(UriStem), Errors=countif(Status >= 400), MaxBytes=max(BytesSent), SampleURIs=make_set(UriStem, 20) by bin(TimeGenerated, 10m), Server, User, ClientIP
| where Requests >= 25 or URIs >= 10 or Errors >= 15
| order by Requests desc
Hunt 7 — Windows Security Event fallback for IIS child processes
SecurityEvent
| where TimeGenerated > ago(30d) and EventID == 4688
| where ParentProcessName endswith "\\w3wp.exe"
| where NewProcessName endswith "\\cmd.exe" or NewProcessName endswith "\\powershell.exe" or NewProcessName endswith "\\pwsh.exe" or NewProcessName endswith "\\rundll32.exe" or NewProcessName endswith "\\regsvr32.exe" or NewProcessName endswith "\\mshta.exe" or NewProcessName endswith "\\cscript.exe" or NewProcessName endswith "\\wscript.exe" or NewProcessName endswith "\\certutil.exe"
| project TimeGenerated, Computer, SubjectUserName, ParentProcessName, NewProcessName, CommandLine, NewProcessId
| order by TimeGenerated desc
Hunt 8 — IIS child process followed by file write or external connection
let SuspiciousChildren = DeviceProcessEvents
| where TimeGenerated > ago(30d) and InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "rundll32.exe", "regsvr32.exe", "mshta.exe", "cscript.exe", "wscript.exe")
| project DeviceId, DeviceName, ProcessId, ProcessTime=TimeGenerated, Child=FileName, ChildCommand=ProcessCommandLine;
let FollowOn = union isfuzzy=true
(DeviceFileEvents | where TimeGenerated > ago(30d) | project DeviceId, ProcessId=InitiatingProcessId, FollowTime=TimeGenerated, FollowType="File", Detail=strcat(FolderPath, "\\", FileName)),
(DeviceNetworkEvents | where TimeGenerated > ago(30d) and ActionType == "ConnectionSuccess" | project DeviceId, ProcessId=InitiatingProcessId, FollowTime=TimeGenerated, FollowType="Network", Detail=strcat(RemoteIP, ":", RemotePort, " ", RemoteUrl));
SuspiciousChildren
| join kind=inner FollowOn on DeviceId, ProcessId
| where FollowTime between (ProcessTime .. ProcessTime + 10m)
| project ProcessTime, FollowTime, DeviceName, Child, ChildCommand, FollowType, Detail
| order by ProcessTime desc
Detection Notes
- Hunts 1, 3, 4, and 8 are highest signal for post-exploitation, but they cannot by themselves attribute entry to CVE-2026-65660.
- No authoritative exploit URI, request body, web-shell name, or campaign IOC was public at preparation time. The IIS hunt deliberately avoids claiming one and should be baselined to each farm.
- SharePoint timer jobs, search, backup, antivirus, administration, and deployment tools can create unusual worker-child or file-write activity. Validate application pool, signer, hash, account, and change window.
W3CIISLogfield casing and connector mappings vary; adaptcolumn_ifexistsaliases to the deployed schema. Reverse proxies can replace the original client IP unless forwarded headers are logged.- Security Event 4688 includes
CommandLineonly when process command-line auditing is enabled. File and network evidence may be absent without endpoint telemetry. - An authenticated exploit may use a valid account and ordinary HTTP status codes; identity and IIS telemetry should be correlated with endpoint behavior.