OffPerimeter · Threat advisories
Campaign advisory
mediumPublished 2026-09-28 · 0 indicators

Exploitation of CVE-2026-65660 in Microsoft SharePoint to deploy webshell backdoors

An unidentified threat actor is actively exploiting a high severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-65660. The campaign targets government entities to establish a foothold within sensitive networks. OffPerimeter analysis indicates the primary objective is the deployment of webshells to maintain persistent access to compromised environments.

ShareXLinkedInWhatsApp
First seen
2026-09-24
Last seen
2026-09-27
Threat actors
—
Malware
webshell
Sectors
Government
Countries
—

How it works

The attack begins with the exploitation of CVE-2026-65660 to achieve remote code execution via code injection. Once the vulnerability is successfully triggered, the actor executes arbitrary commands to facilitate the deployment of a webshell. This webshell is then used to provide a persistent backdoor for subsequent command and control or data exfiltration activities.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp