BoletimSecSeptember 23, 2026🇵🇹Translated from Portuguese

Critical Microsoft SharePoint Vulnerability Allows Remote Code Execution via SafeControls Bypass

A vulnerability in Microsoft SharePoint Server allows an authenticated attacker with low privileges to execute arbitrary code on the server. Identified as CVE-2026-65660, the flaw received a CVSS score of 8.8.

The affected products are SharePoint Server 2016, SharePoint Server 2019, and the Subscription Edition, meaning on-premises deployments maintained within organizations' own infrastructure.

The issue lies in an injection that bypasses the SafeControls protection, a mechanism intended to restrict which classes can be registered and executed by the application. Exploitation occurs in the ToolPane component. When processing attacker-controlled Register directives, quotes in the content are not handled properly, allowing extra directives to be inserted after security validations have passed.

This enables the attacker to register dangerous .NET classes and achieve arbitrary code execution through deserialization, starting from a standard user account without requiring administrative privileges.

Microsoft published fixes on August 11, 2026, with specific versions for each product line. At the time of disclosure, the company stated the flaw had not been publicly disclosed or exploited in attacks. This situation changed with the release of a detailed technical analysis of the vulnerability.

With the mechanics of the flaw now documented, the risk of exploitation has increased for organizations still running unpatched servers.

Related articles

AntiMalwareVulnerabilities & Exploits

Google Chrome Prepares Deferred Restart Feature to Apply Security Updates Without Disruption

Google is developing a queued restart capability for Chrome that lets the browser install updates after detecting user inactivity instead of forcing an immediate closure. The feature, tracked under the queued-restarts theme in Chromium code, offers users the choice to restart right away or wait for roughly five minutes of idle time. Chrome will automatically skip the restart if the browser is downloading files, playing audio or video, recording the screen, or using the camera. Notifications and a menu indicator labeled Scheduled Restart will inform users of the planned update, while additional reminders may appear when opening new tabs. The implementation currently lacks the ability to select a precise restart time like Windows Update and remains limited to the absence of activity. Google has previously committed to reducing the annoyance of mandatory browser restarts for security patches, though the feature has not yet reached the stable channel.

AntiMalwareVulnerabilities & Exploits

Windows 11 Update KB5124010 Triggers Crashes in Battlefield 6 and Other Titles

An optional non-security update KB5124010 for Windows 11 versions 24H2 and 25H2 is causing sudden game crashes for players of Battlefield 6, Battlefield 2042, and titles using Easy Anti-Cheat. The patch, initially distributed to Windows Insider participants and later made available broadly in early September, leads to silent exits within 15-30 seconds or a few minutes after launch. Reinstalling games, verifying DirectX installations, and repairing anti-cheat components have failed to resolve the issue, while uninstalling KB5124010 has restored functionality in multiple cases. The crashes are suspected to stem from conflicts with anti-cheat systems, including Electronic Arts' Javelin used in Battlefield titles and Easy Anti-Cheat in games such as Wardogs, which reports error WD-L020-95bc94d86a0d. Microsoft has not officially confirmed any link to anti-cheat software, and the problems affect users across diverse hardware configurations. Players are advised to skip the optional update until further clarification or a fix is provided.

Security NEXTVulnerabilities & Exploits

WordPress Issues Critical Security Update 7.1.2 Five Days After Previous Patch

WordPress has released version 7.1.2 to fix a new critical vulnerability that was not addressed in the 7.1.1 update issued just five days earlier. The flaw, tracked as CVE-2026-87902, is a path traversal issue rated Critical that can be exploited without authentication. It resides in the page template resolution process and allows execution of arbitrary local PHP files located outside the theme directory, provided certain conditions such as the presence of a page- prefixed directory in the parent or child theme are met. The update was published on September 22, 2026, and affects the prior release from September 17. Administrators are urged to apply the patch immediately to prevent potential remote code execution.

Security NEXTVulnerabilities & Exploits

F5 BIG-IP APM Vulnerability CVE-2026-94127 Allows Remote Code Execution, Already Exploited in the Wild

F5 has disclosed a critical heap-based buffer overflow vulnerability in BIG-IP Access Policy Manager that is already being actively exploited. The flaw, tracked as CVE-2026-94127, affects systems configured as an OAuth authorization server with both an access policy and OAuth profile applied to a virtual server. Successful exploitation can result in arbitrary code execution from crafted network traffic. The issue also impacts appliance mode configurations. F5 rates the vulnerability 9.3 under CVSS v4.0 and 9.8 under CVSS v3.1, classifying it as Critical. The company discovered the flaw internally and has confirmed real-world exploitation, urging immediate patching and compromise assessment.