Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-65660-Poc — Malicious Register Directive Code Injection Exploit | Kitploit
Tools/GitHubGitHub/shadowforge-cyber/cve-2026-65660-poc
Privilege EscalationPersistence MechanismsExploitationLateral MovementWeb Application ExploitationData ExfiltrationPost-ExploitationWeb SecurityCommand and Control

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Payload Development
Remote Access Trojan
GitHubshadowforge-cyber/cve-2026-65660-poc

CVE-2026-65660-Poc

Malicious Register Directive Code Injection Exploit

View Repository
12 days agoNot yet reviewed

MS SharePoint CVE-2026-65660 - Malicious Register Directive Code Injection Exploit

Description

This repository provides a production-ready exploit for CVE-2026-65660 (Improper Control of Generation of Code, CWE-94) in Microsoft SharePoint Server. The vulnerability stems from unescaped quote injection into Register directives, bypassing SafeControls validation and enabling arbitrary code execution via XamlServices.Parse() deserialization.

The exploit allows an authorized low-privilege user to inject malicious directives, achieve remote code execution, deploy a persistent in-memory webshell, escalate privileges via SharePoint service context, perform lateral movement in the farm, establish C2, exfiltrate sensitive documents/data, and disrupt collaboration services.

Download

Contact us for private access: [email protected]

Requirements

  • Microsoft SharePoint Server 2016/2019/2022 (on-prem)
  • .NET Framework 4.8+
  • Python 3.10+
  • Requests library (for HTTP/XAML interaction)

Features

  • Direct exploitation of CVE-2026-65660 via malicious Register directive injection
  • In-memory webshell deployment for persistence
  • Privilege escalation through SharePoint service context
  • Lateral movement and command-and-control establishment
  • Document and data exfiltration
  • Operational disruption capabilities

Installation

root@kitploit:~
pip install requests
python exploit.py [options]

Credits

Report & PoC: ShadowForge Cyber

Download Tool