DEV Community

Anoymask
Anoymask

Posted on

SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access

1. Overview

  • Article Title: CVE-2026-65660: Previdian observes two-stage SharePoint exploitation attempts
  • Publisher: Previdian
  • Publication Date: September 24, 2026
  • Original Update Date: September 25, 2026
  • Original Source: Previdian
  • Related Information Sources: Microsoft Security Response Center: CVE-2026-65660, Viettel Cyber Security: SharePoint CVE-2026-65660, SecurityWeek, Microsoft CNA / CISA ADP: CVE-2026-65660, CISA: Known Exploited Vulnerabilities catalog data, Microsoft Learn: IIS logFile
  • Related Malware, Attack Groups, CVEs, and Products: sphealth.aspx, SdLoader, CVE-2026-65660, Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
  • Severity: Critical (Active exploitation confirmed and added to CISA KEV. While the vulnerability itself is a high-severity RCE requiring low-privileged authentication, it can become an unauthenticated RCE when chained with a separate delivery vector on anonymously accessible sites.)
  • Revision Notes: Separated the anonymous delivery vector fix from the main CVE patch, clarified product-specific patching boundaries, clarified that the observations comprised 12 requests, detailed payload analysis and execution success, and specified IIS logging conditions. Aligned active exploitation evidence with official CISA data and updated the original update date.

2. Executive Summary

Previdian observed attacks attempting to deliver XAML deserialization payloads and create web shells without authentication by chaining SharePoint type-checking bypass CVE-2026-65660 with a separate anonymous access issue. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 25.

3. Attack Flow

The observed attacks attempt to compromise systems by chaining an anonymous access vector with the vulnerability (CVE-2026-65660) using a two-stage payload. The role and observation status of each stage are detailed below.

Comparison of Observed Two-Stage Payloads

Stage Payload Role and Technical Elements HTTP Request Body Size Observed Facts and Verification Status
Stage 1 Type-checking disable attempt (ActivitySurrogateDisableTypeCheck) 7,834 bytes Serialization format attempting to bypass checks. Success in bypassing constraints in real environments remains unconfirmed
Stage 2 DLL decryption and memory loading (SdLoader) 535,404 bytes Gadget containing an encrypted DLL. Based on static payload analysis; execution success in honeypot environments is unconfirmed

Two-Stage Attack Chaining Anonymous Access Vector and CVE-2026-65660

  1. Attackers send a POST request to the WebPart editing endpoint without an authentication cookie to SharePoint sites that allow anonymous viewing, passing crafted WebPart data with DisplayMode=Edit.
  2. By routing through a separate anonymous delivery issue (patched in June), the payload reaches the ToolPane handler, which normally requires authentication. Note that even in environments without anonymous access, attackers with valid low-privileged credentials can exploit CVE-2026-65660 independently.
  3. The first-stage payload (ActivitySurrogateDisableTypeCheck) attempts to disable type checking. The observed payload uses a serialization format distinct from public research, and it remains unconfirmed whether constraints were successfully bypassed in real environments.
  4. The second-stage payload (ActivitySurrogate gadget, encrypted DLL, and SdLoader) attempts to decrypt the DLL and load it into memory using Assembly.Load(byte[]). This is based on static functional analysis of the payload and does not imply successful actual execution.
  5. In its September 25 update, Previdian reported an attempt to create a web shell at /_layouts/15/sphealth.aspx. Successful final code execution in its honeypot remains unconfirmed.

4. Attacker Position and Execution Location

  • Attackers reach on-premises SharePoint from external networks. Exploitation requires no authentication on anonymous sites via vector chaining, or low-privileged authentication for CVE-2026-65660 alone.
  • Code executes within the IIS or SharePoint worker process or under its service privileges. Specific permissions depend on the farm configuration.

5. Visibility for Victims and Administrators

Victims

  • End-user screens may show no clear visible changes. This attack does not compromise user devices simply by viewing anonymous pages.

Administrators

  • IIS access logs should be checked for target URIs and DisplayMode=Edit. Capturing cookies and received byte counts requires specific log configuration settings, and POST bodies such as MSOTlPn_Uri or MSOTlPn_DWP require additional logging; standard settings alone cannot determine the absence of cookies or payload contents. sphealth.aspx, suspicious DLLs, and w3wp behavior also serve as indicators.

6. Success and Failure Conditions

Success Conditions

  • The August 11 updates remain unapplied on SharePoint Server 2016, 2019, and Subscription Edition.
  • For standalone exploitation, valid low-privileged authentication is required. For the observed pre-authentication chain, both the anonymous delivery issue patched on June 9 and the core CVE vulnerability patched on August 11 must be unpatched on an anonymously accessible site.
  • The XAML gadget and subsequent payload are not blocked by defenses and are successfully loaded and executed under service privileges.

Failure Conditions and Risk Mitigation

  • Install the applicable update packages and complete the required configuration procedures across all servers. The core CVE patch boundaries are 16.0.5565.1001 for 2016, 16.0.10417.20198 for 2019, and 16.0.19725.20522 for Subscription Edition. Verify the June anonymous delivery patch as well to remediate both issues.
  • Disable unnecessary anonymous access and restrict external exposure to required sites and sources. This does not replace patching for standalone authenticated RCE.
  • Preserve IIS request bodies and URIs, SharePoint ULS logs, processes, file integrity, and outbound communications to monitor for ASPX creation in web-accessible areas and abnormal execution from w3wp.

7. Impact Upon Success

  • Arbitrary .NET code may execute on the SharePoint server, potentially deploying a web shell.
  • Inference: This could lead to the acquisition of documents, configurations, and sensitive information accessible via service privileges, or lateral movement to connected systems.
  • While CISA KEV listing indicates active exploitation, it cannot be generalized to data theft or external exfiltration at individual organizations.

8. Observable Logs

  • Email: No reports indicate email was used for initial access.
  • Proxy / SWG / DNS: Identify POST requests containing AddGallery.aspx, designgallery.aspx, and DisplayMode=Edit in IIS or reverse proxies. Confirming the presence of cookies, request size, and XAML bodies requires respective logging configurations. Absence of cookie logging must not be treated as an absence of cookies.
  • Endpoint / EDR: Detect abnormal child processes of w3wp.exe, in-memory Assembly loading, and the creation or loading of sphealth.aspx, wt3k3sij.dll, and 24e5mo4s.dll. In-memory execution may occur without creating files on disk.
  • Identity / IdP: Anonymous chaining can succeed without authentication logs. Separately verify the misuse of low-privileged accounts and subsequent use of service credentials.
  • SaaS / Cloud: Track anomalies via on-premises SharePoint ULS logs, auditing, configuration changes, and document access. The cited public sources do not establish that this vulnerability affects Microsoft 365 SharePoint Online.
  • Network: Monitor for unknown outbound traffic originating from SharePoint servers, internal reconnaissance, and increases in SMB, WinRM, or database connections.

9. Determining Attack Success

Public Information: CISA added the vulnerability to KEV on September 25, indicating active exploitation. This announcement and the success or failure of individual requests observed by Previdian must be evaluated separately.

  • Attack Attempt Observed (Success Unconfirmed): Public Information: Previdian observed a total of 12 POST requests sending two payload types across 6 paths, and added an analysis regarding web shell creation on September 25. Successful final code execution in a honeypot environment has not been confirmed. (Target: Previdian SharePoint honeypot)
  • Initial Execution Confirmed: Criteria: Verify execution using suspicious Assembly loads within w3wp, child processes, DLL loads, and corresponding responses. HTTP 200 responses alone are insufficient. (Target: Organization's SharePoint)
  • Subsequent Compromise Confirmed: Criteria: Independently verify web shell creation and access, credential usage, document retrieval, internal connections, and external exfiltration. (Target: Organization's farm, authentication, and communication logs)

10. Investigation Playbook

  • Investigation Starting Point: Start with unpatched CVE-2026-65660, editing requests without cookies, sphealth.aspx, suspicious DLLs, or w3wp behavior.
  • Initial Checks: Verify patch status across all servers, anonymous access settings, external exposure, IIS log retention, and whether web-root files and ULS logs have been preserved.
  • Endpoint and Server Investigation: Examine IIS logs, ULS, w3wp memory and processes, the web root, GAC, temporary directories, and public DLL hashes across the entire farm.
  • Authentication and Cloud Investigation: Separate anonymous and authenticated paths to evaluate exposure of low-privileged accounts, farm and service accounts, and ASP.NET machine keys or integrated credentials.
  • Tracking Subsequent Actions: Trace mass document retrieval, searches, administrative modifications, database queries, internal connections, and outbound traffic.
  • Containment: Restrict external exposure and anonymous access, apply patches after preserving evidence, and if compromise is confirmed, do not stop at removing web shells; restore the farm and credentials to a trusted state.
  • Categorization: Separately record payload delivery, type-checking bypass, code execution, web shell creation, document retrieval, external exfiltration, and lateral movement.

11. Defense and Detection Ideas

  • Single Events: Detect ToolPane editing requests without cookies, oversized MSOTlPn_DWP payloads, creation of unknown ASPX files in the web root, and shell launching from w3wp.
  • Time-Series Correlation: Correlate first-stage and second-stage POST requests, DLL loading, web shell creation and access, and subsequent communications.
  • Threat Hunting: Retroactively search for sphealth.aspx, public DLL hashes, ActivitySurrogateDisableTypeCheck, ObjectDataProvider, and ExpandedWrapper.
  • Log Limitations: Without request-body logs or telemetry on w3wp memory activity, distinguishing payload delivery from execution becomes more difficult. Correlate any available process, response, and file evidence. Fileless execution may evade detections reliant solely on ASPX file creation.
  • Prioritized Mitigations: Prioritize applying Microsoft patches, restricting anonymous access, reducing external exposure, monitoring w3wp behavior, and rotating credentials upon compromise.

12. Facts, Inference, and Hypothesis

Facts

  • Microsoft evaluated CVE-2026-65660 as a code injection vulnerability in SharePoint allowing low-privileged authenticated attackers to execute arbitrary code without user interaction, and released a patch on August 11, 2026.
  • CISA added the vulnerability to KEV on September 25, 2026, setting a remediation deadline of September 28 for affected U.S. federal agencies. While KEV listing indicates active exploitation, it does not specify individual execution results or scale of impact.
  • Previdian's technical analysis explains that the type-checking bypass leveraging SafeControls quote handling matches Viettel's public methodology. The anonymous delivery issue was patched on June 9, and the core CVE was patched on August 11; they have separate prerequisite conditions.
  • Previdian observed a total of 12 POST requests sent from the same source across 6 paths. Lacking cookies and Authorization headers, these represent attempted chained exploitation relying on anonymous viewing and two unpatched issues.
  • The observed attack structure involved attempting to disable type checking in a 7,834-byte first stage, and delivering an ActivitySurrogate gadget, an encrypted DLL, and SdLoader in a 535,404-byte second stage. Both figures represent HTTP request body sizes, not the size of the DLL itself.
  • The September 25 update reported an attempted web shell creation at /_layouts/15/sphealth.aspx. Although payload delivery to the honeypot was observed, successful final code execution in that environment has not been confirmed.

Inference

  • Even if anonymous access is disabled, environments with compromised low-privileged accounts remain at risk of standalone authenticated RCE via CVE-2026-65660.
  • Following web shell creation attempts, threat actors may proceed to steal documents and sensitive information or perform internal lateral movement, depending on service account privileges and SharePoint farm connectivity.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "14. Open Questions and Further Investigation."

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application high Crafted POST requests are sent to public SharePoint WebPart processing, chaining an anonymous access vector with CVE-2026-65660.
T1505.003 Server Software Component: Web Shell high Previdian observed an attempt to create a web shell at sphealth.aspx. Execution success requires separate verification.
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File medium The second-stage payload contained an AES-encrypted DLL.

14. Open Questions and Further Investigation

  • The full scope of threat actors, number of victim organizations, and attack start times.
  • Whether the final payload executed in Previdian's honeypot, and how many web shell creations succeeded in production environments.
  • The scope of post-installation credential theft, document access, internal lateral movement, and external exfiltration.

15. Impact on SOCs and Organizations

Organizations operating on-premises SharePoint should immediately verify that the applicable security updates addressing this vulnerability have been installed. Sites permitting anonymous browsing may allow pre-authentication chaining, but disabling anonymous access does not eliminate the risk of standalone low-privileged authenticated RCE. Investigate IIS requests, SharePoint logs, w3wp child processes, web root ASPX files, and related DLLs across the entire farm, and consider rotating ASP.NET machine keys and service credentials if compromise is confirmed.

16. Summary by Role

  • For SOCs: Correlate cookie-free POST requests to AddGallery.aspx and designgallery.aspx, DisplayMode=Edit, large WebPart payloads, sphealth.aspx creation, and abnormal w3wp behavior.
  • For Administrators: Apply Microsoft updates from August 11 onward to all SharePoint servers, and disable or restrict anonymous browsing. If signs of compromise are found, investigate the entire farm and credentials.
  • For End Users: This is a server-side attack requiring no user interaction. Emergency remediation by on-premises SharePoint administrators is required.

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments. Some comments have been hidden by the post's author - find out more