SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Today’s signal The Hacker News recently reported SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE. Published context: September 22, 2026. A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edit ...