Work Expertise Process About Notes Contact on LinkedIn

Note

The advisory still says no

The prose and the checkbox disagree, and the checkbox is what most dashboards read.

Microsoft’s August patch for CVE-2026-65660 was filed as SharePoint code injection. On 25 September the advisory gained a line: as of that date, Microsoft had reliable evidence of observed attacks. CISA put it on the KEV list the same day and told civilian federal agencies to finish by 28 September, with forensic triage attached, not just a version bump. SecurityWeek, this morning, notes Previdian saw exploitation attempts on the 24th and attempts to drop a webshell on the 25th, after Viettel published technical detail. Microsoft still rates it as authenticated: low-privilege access on the server, no extra click. Unauthenticated code execution means chaining it to something else.

The structured fields did not move with the sentence. Reporting on the revised record says exploited is still no, and the temporal score still treats the exploit as unproven.

Why the ticket will close green

A scanner that keys off the exploited flag will not open this. A change window that “applied August” in August is already late if the farm never actually took the build. A ticket that only checks the build number, and does not look for a webshell from the 25th, meets the patch half of CISA’s sentence and misses the triage half.

Sixteen SharePoint bugs are already on the KEV list. This one is not special because the number is scary. It is special because the vendor told you, in English, that attacks were observed, and told your tools, in the field, that they were not.

What to pull before calling it patched

The build, then the content. New files on SharePoint servers around 24–25 September. Accounts that had only site-level rights and suddenly reached code. Do not wait for the exploited flag to flip. The deadline on the KEV entry is tomorrow for federal civilian agencies. Everyone else with a SharePoint farm is on the same calendar without the order.

If your report says not exploited because Microsoft’s field says not exploited, you read the wrong line of the same page.

Cite: Fabio Correia, “The advisory still says no”, 2026-09-27. https://www.fabiocti.com/notes/the-advisory-still-says-no/. Markdown: https://www.fabiocti.com/notes/the-advisory-still-says-no.md

Comments

Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.

No public replies yet.

Add a comment
All notes