[Webinar] New in Endpoint Security-Hear from a Security Leader & IDC AnalystOn October 13, SentinelOne is hosting a virtual event with featured speakers from IDC and Franklin Mountain Management. They’ll be discussing the questions practitioners and security leaders actually want answered. Hear first hand how one security leader protects a complex, multi-industry enterprise with a lean team. SharePoint exploitation featured in the first _secpro CISO Update because a compromised collaboration server can support a much wider intrusion. Two recent reports explain different parts of this risk: Previdian’s observations of attempts against CVE-2026-65660, and Symantec and Carbon Black’s investigation of Warlock ransomware. They should be read together, but their findings must remain separate. Neither report establishes that Warlock used CVE-2026-65660 in the documented intrusion. What CVE-2026-65660 allowsThe Canadian Cyber Centre describes CVE-2026-65660 as a CWE-94 code-injection vulnerability affecting SharePoint Server. An authenticated attacker can execute arbitrary code. When combined with separate SharePoint weaknesses, it can support pre-authentication execution on sites permitting anonymous access. That condition matters: anonymous access does not make the CVE itself an authentication bypass. [3] Code injection crosses the boundary between application data and executable instructions. In a collaboration platform, permission to submit or configure content should not confer permission to execute server-side code. The operational consequence depends on the privileges and network access of the affected process. Investigators therefore need to establish which identity executed the payload and what that identity could reach. Table 1. Fixed-version thresholds published by the Canadian Cyber Centre |