Skip to content
ThreatCluster

Critical Remote Code Execution Vulnerabilities in SENAITE and SharePoint

First seen 25 Sep 2026, 15:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 16:28 UTC
  • •CVE-2026-54569 affects SENAITE with remote code execution capabilities.
  • •CVE-2026-65660 is actively exploited in the wild, confirmed by CISA.
  • •Immediate updates to Security Gateway products are essential for protection.

Two critical remote code execution vulnerabilities have been identified in SENAITE and Microsoft SharePoint. The SENAITE vulnerability (CVE-2026-54569), published on August 26, 2026, allows attackers to execute arbitrary code on affected systems. The Microsoft SharePoint vulnerability (CVE-2026-65660), published on August 11, 2026, was added to the CISA KEV list on September 25, 2026, indicating active exploitation. Both vulnerabilities affect multiple versions of security gateways, including R81, R80, R77, and R75. Security professionals are urged to update their systems immediately to mitigate these risks. The attack vectors involve exploiting weaknesses in web server enforcement and Windows SMB protocols. Logs will indicate violations related to these attacks. The situation is critical, with active exploitation confirmed for SharePoint.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-11
CVE-2026-65660 published
Microsoft SharePoint vulnerability disclosed, allowing remote code execution.
Advisories.Checkpoint
2026-08-26
CVE-2026-54569 published
SENAITE vulnerability disclosed, enabling remote code execution on affected systems.
Advisories.Checkpoint
2026-09-25
CVE-2026-65660 added to CISA KEV
CISA confirmed active exploitation of the Microsoft SharePoint vulnerability.
Advisories.Checkpoint
2026-09-25
First public PoC for CVE-2026-65660
Proof-of-concept code for the SharePoint vulnerability released, increasing risk of exploitation.
Advisories.Checkpoint

More articles in this cluster (4)

Following this threat?

Track CVE-2026-54569 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed