Exploitation of CVE-2026-65660 in Microsoft SharePoint to deploy webshell backdoors
An unidentified threat actor is actively exploiting a high severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-65660. The campaign targets government entities to establish a foothold within sensitive networks. OffPerimeter analysis indicates the primary objective is the deployment of webshells to maintain persistent access to compromised environments.
- First seen
- 2026-09-24
- Last seen
- 2026-09-27
- Threat actors
- —
- Malware
- webshell
- Sectors
- Government
- Countries
- —
How it works
The attack begins with the exploitation of CVE-2026-65660 to achieve remote code execution via code injection. Once the vulnerability is successfully triggered, the actor executes arbitrary commands to facilitate the deployment of a webshell. This webshell is then used to provide a persistent backdoor for subsequent command and control or data exfiltration activities.
Techniques (MITRE ATT&CK)
- T1059 · ExecutionCommand and Scripting InterpreterThe actor uses code injection to execute arbitrary commands on the SharePoint server.
- T1505.003 · PersistenceWeb ShellA webshell is deployed to the web server to maintain long term access to the target system.
What to do
- Apply all available security patches for Microsoft SharePoint immediately.
- Implement strict web application firewall rules to detect and block suspicious code injection patterns.
- Monitor SharePoint server directories for the unauthorized creation of new web files or scripts.
- Audit web server logs for unusual command execution or unexpected administrative activity.
- Restrict outbound network traffic from SharePoint servers to minimize potential command and control communication.