hacker-news · Crawled Sep 22, 2026

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Read original article ↗

AI Summary

A vulnerability in SharePoint Server, tracked as CVE-2026-65660, initially misclassified by Microsoft as a spoofing flaw, actually enables authenticated remote code execution. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition, and stems from improper handling of double quotes in web-part markup within the ToolPane component, allowing arbitrary .NET class registration and subsequent code execution via XamlServices.Parse() deserialization. Researcher Dinh Ho Anh Khoa demonstrated the exploit and noted it could be chained with a previously patched authentication bypass to achieve pre-authentication RCE on anonymously accessible servers. Although no in-the-wild exploitation has been reported, the full exploit is public, and the patch was released in Microsoft's August 11 updates.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.