SharePoint RCE దాడుల్లో ఉపయోగిస్తున్నారు: సంస్థలు ఇప్పుడు ఏమి నిర్ధారించాలి

CVE-2026-65660 active exploitation లో ఉంది, remediation deadline ముగిసింది. SharePoint teams update install అయిందో లేదో మాత్రమే కాకుండా మరిన్ని అంశాలను పరిశీలించాలి.

ఈ భాషల్లో చదవండి: English · తెలుగు · हिन्दी

A protected SharePoint server sits at the centre of connected identity, document, workflow and infrastructure paths, with a warning signal showing active exploitation.

ఒక SharePoint నిర్వాహకుడు నెలవారీ భద్రతా జాబితాను పరిశీలిస్తున్నప్పుడు, spoofing సమస్యగా వివరించిన ఒక vulnerability కనిపిస్తుంది. Update ముఖ్యమైనదే. కానీ outages, application releases, ఇతర critical patches మధ్య అది వెనుకబడవచ్చు. కొన్ని వారాల తరువాత అదే vulnerability ను remote code execution గా మార్చి వివరించారు. దాన్ని దాడుల్లో ఉపయోగిస్తున్నట్లు కూడా నిర్ధారించారు.[1]

CVE-2026-65660 విషయంలో జరిగిన operational సమస్య ఇదే.[4]

Microsoft 11 August 2026న fixes విడుదల చేసింది. తరువాత ఈ సమస్యను code injection vulnerability గా వర్గీకరించింది. Authenticated attacker దీనిని ఉపయోగించి network ద్వారా code execute చేయగలడు. 25 September నాటికి attacks జరిగినట్లు Microsoft వద్ద నమ్మదగిన ఆధారాలు ఉన్నాయి. CISA దీనిని Known Exploited Vulnerabilities catalog లో చేర్చి, 28 September ను remediation deadline గా నిర్ణయించింది.[3]

ఆ గడువు ముగిసింది. తమ farms సురక్షితంగా ఉన్నాయని ఇంకా నిర్ధారించని బృందాలు దీనిని సాధారణ patch cycle లోని పనిగా కాకుండా incident-response పనిగా చూడాలి.

సమస్య తీవ్రమైనదే, కానీ attacker ఎలా చేరుకుంటాడో ముఖ్యం

CVE-2026-65660 SharePoint Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition ను ప్రభావితం చేస్తుంది. దీని CVSS score 8.8.[1]

సాధారణ attack కు authenticated account అవసరం. అందువల్ల urgency తగ్గదు. SharePoint ను employees, contractors, service accounts, external collaborators ఉపయోగిస్తారు. Attacker authentication ను నేరుగా break చేయకపోయినా, దొంగిలించిన credentials లేదా low-privilege account ద్వారా లోపలికి రావచ్చు.

Anonymous access అనుమతించిన servers లో ఇతర SharePoint vulnerabilities తో chain చేసినప్పుడు, pre-authentication remote code execution సాధ్యమని Canadian Centre for Cyber Security హెచ్చరించింది.[2] అందుకే teams software version తో పాటు ప్రతి web application ఎలా exposed అయిందో కూడా పరిశీలించాలి.

ముందుగా ప్రతి server fix అయిందని నిరూపించండి

Patch-management dashboard లో job successful అని కనిపించడం మాత్రమే సరిపోదు. ప్రతి SharePoint farm లోని ప్రతి server ను inventory చేసి, installed build ను fixed version తో పోల్చండి.

SharePoint edition Fixed version
SharePoint Enterprise Server 2016 16.0.5565.1001
SharePoint Server 2019 16.0.10417.20198
SharePoint Server Subscription Edition 16.0.19725.20522

ప్రతి server కు evidence నమోదు చేయండి. ఒక server current గా ఉందని మొత్తం farm fixed అయిందని భావించవద్దు. మిగిలిపోయిన application server, search server లేదా disaster-recovery node vulnerable path ను కొనసాగించవచ్చు.

Update తరువాత Microsoft సూచించిన SharePoint update procedure ను పూర్తిచేయండి. అన్ని servers సరైన build ను చూపుతున్నాయో నిర్ధారించండి. Farm ఆరోగ్యంగా ఉందో, configuration పని మధ్యలో ఆగలేదో కూడా పరిశీలించండి.

తరువాత access path ను పరిశీలించండి

SharePoint URL public గా ఉందా అనే ఒక్క ప్రశ్న సరిపోదు. పూర్తి access path ను చూడాలి.

  • Internet లేదా partner networks నుంచి ఏ web applications అందుబాటులో ఉన్నాయి?
  • ఎక్కడైనా anonymous access enabled గా ఉందా?
  • Farm ముందు ఏ reverse proxies, load balancers లేదా web application firewalls ఉన్నాయి?
  • Original inventory లో లేని publishing, collaboration లేదా legacy sites ను low-privilege users చేరగలరా?
  • SharePoint కు ఏ service accounts, automation tools connect అవుతున్నాయి?

Patching పూర్తయ్యే వరకు public access ను పరిమితం చేయడం, అవసరం లేని anonymous access ను నిలిపివేయడం, trusted networks కు entry points ను తగ్గించడం ఉపయోగపడుతుంది. ఇవి risk ను తగ్గిస్తాయి. కానీ update కు ప్రత్యామ్నాయం కావు.

Patch చేశామని exploitation జరగలేదని చెప్పలేం

CISA deadline కు ముందే exploitation కనిపించింది. కాబట్టి ఇప్పుడు patched అయిన server ను కూడా investigate చేయాల్సి రావచ్చు.

Server vulnerable గా ఉన్న కాలానికి సంబంధించిన SharePoint, IIS activity ను చూడండి. Windows security events, endpoint detection alerts, identity sign-ins, process execution, outbound network connections తో వాటిని correlate చేయండి. సాధారణంగా పరిమిత SharePoint పనులు మాత్రమే చేసే accounts కు సంబంధించిన అసాధారణ activity పై ప్రత్యేకంగా దృష్టి పెట్టండి.

Generic checklist ను కల్పిత indicators of compromise గా మార్చవద్దు. Microsoft, CISA guidance తో పాటు మీ security tools లోని evidence ను ఉపయోగించండి. Suspicious execution కనిపిస్తే files తొలగించడానికి లేదా server rebuild చేయడానికి ముందు evidence ను preserve చేయండి. Incident-response team ను చేర్చి credentials, connected systems, ఇతర farm servers వరకు review ను విస్తరించండి.

SharePoint ఎందుకు పెద్ద blast radius సృష్టిస్తుంది

SharePoint ను collaboration platform అని పిలుస్తారు. కానీ అది contracts, operational documents, employee records, workflow data, ఇతర business systems కు links కలిగి ఉండవచ్చు. Databases, file shares, mail systems లేదా automation services ను చేరగల identities తో అది నడవవచ్చు.

అందువల్ల ఒక server compromise రెండు risks ను సృష్టిస్తుంది. మొదటిది SharePoint content కు access. రెండవది credential theft, persistence లేదా connected systems లోకి movement కోసం ఆ server ను ప్రారంభ స్థలంగా ఉపయోగించడం.

Response team నాలుగు boundaries ను map చేయాలి: content, identity, automation, network access. కేవలం SharePoint patch review చేస్తే compromise విలువను పెంచే connected systems కనిపించకపోవచ్చు.

SharePoint blast-radius map A SharePoint Server farm connects to identities, business content, automation and infrastructure. Internet and partner access form an outer exposure boundary. SharePoint blast-radius map TechiesJournal Prasad Kukkala 2026-09-29 sharepoint-rce-v1-2026-09-29 A SharePoint Server farm connected to identity accounts, business documents, workflows, databases and file shares, with Internet and partner access shown as an external boundary. Copyright 2026 TechiesJournal. All rights reserved. Internet and partner access SharePoint Server Farm and service identities Identity Users and service accounts Business content Documents and records Automation Workflows and integrations Infrastructure Databases and file shares Patch the server. Investigate every trust path. TechiesJournal
Figure 1: SharePoint server identities, sensitive content, automation, infrastructure తో connected గా ఉండవచ్చు. Incident review ఆ trust paths అన్నింటినీ పరిశీలించాలి.
Figure 1 కోసం అందుబాటులో ఉన్న వివరణ

మధ్యలో SharePoint Server farm, దానికి identity accounts, business documents, workflows, databases, file shares connections, బయట Internet మరియు partner access boundary చూపించే చిత్రం.

Hybrid environment కు పాఠం

Collaboration ను Microsoft 365 కు మార్చినంత మాత్రాన on-premises risk ముగియదు. Workflows, archives, custom applications లేదా migrate చేయడం కష్టమైన integrations కోసం పాత farms కొనసాగుతుంటాయి.

అవి తక్కువగా కనిపించినా, ఇంకా ముఖ్యమైన systems తో connected గా ఉండవచ్చు. ప్రతి farm కు owner ను నిర్ణయించండి. అది ఎందుకు కొనసాగుతోంది, ఎవరు access చేయగలరు, ఏ systems దాన్ని trust చేస్తున్నాయి, తదుపరి review ఎప్పుడు జరుగుతుందో నమోదు చేయండి.

CVE-2026-65660 emergency patch సమస్య. అదే సమయంలో, internal collaboration server కూడా production-level authority కలిగి ఉండవచ్చని గుర్తుచేస్తుంది. Browser లో కనిపించే సాధారణ label ఆధారంగా కాకుండా, ఆ server ఏమి చేరగలదో ఆధారంగా దాన్ని రక్షించాలి.

మరింత తెలుసుకోవడానికి

  1. CVE-2026-65660 Microsoft Security Update Guide, Microsoft. ↩
  2. Canadian Centre for Cyber Security alert. ↩
  3. CISA Known Exploited Vulnerabilities Catalog. ↩
  4. CVE-2026-65660 record, CVE Program. ↩
సవరణను తెలియజేయండి

సవరణలు ఎడిటర్‌కు చేరుతాయి; అవి ఎప్పుడూ ఆటోమేటిక్‌గా ప్రచురించబడవు. ఖాతా అవసరం లేదు.