VMTech
Discuss a project →

CISA adds exploited SharePoint and MikroTik flaws to KEV

CISA adds exploited SharePoint and MikroTik flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog after finding evidence of active exploitation. The entries are CVE-2026-65660, a SharePoint code-injection vulnerability with a CVSS score of 8.8, and CVE-2026-67279, a RouterOS workflow-enforcement flaw rated 6.9.

CISA’s action puts both issues among vulnerabilities requiring particular attention from defenders. Federal Civilian Executive Branch agencies have until September 28, 2026, to apply the necessary fixes.

SharePoint advisory updated to remote code execution

CVE-2026-65660 affects Microsoft Office SharePoint. Microsoft initially described the issue as a spoofing vulnerability affecting SharePoint Server, but later updated its advisory to say an authorized attacker could exploit it to execute code over a network.

Microsoft stated that, as of September 25, 2026, it had reliable evidence of observed attacks targeting the vulnerability. The company has not identified the actors behind the activity, when exploitation began, the number of organizations targeted or compromised, or the actions taken after access was obtained.

The revised classification matters because remote code execution changes the operational risk for organizations running affected SharePoint deployments. Teams need to treat the vulnerability as an active intrusion concern rather than relying on its original spoofing label.

RouterOS chain can take over exposed routers

The RouterOS issue, CVE-2026-67279, concerns improper enforcement of behavioral workflow. It can allow an unauthenticated client to open a session channel and send an exec request. CERT Polska reported that it has been chained with CVE-2026-86060, an argument-injection vulnerability in the RouterOS login process, in an exploit called MikroTrick.

By combining the two flaws, an attacker can obtain full unauthenticated access to the administrative console of a susceptible internet-exposed router. CERT Polska said CVE-2026-67279 enables the creation of a session channel before authentication, while CVE-2026-86060 lets an attacker supply login with an attacker-controlled policy mask.

Bishop Fox reproduced the complete administrative takeover against vulnerable RouterOS 7.x builds. Researcher Emilio Gallegos described the chain as two failures at different trust boundaries: one exposes functionality intended only after login, and the other makes the login process treat data from that connection as a trusted administrative identity.

CISA had already added CVE-2026-86060 to KEV on September 11, 2026. Organizations should identify affected SharePoint and RouterOS assets, prioritize vendor fixes, reduce unnecessary internet exposure, and investigate signs of unauthorized administrative or session activity as part of their remediation process.

#cybersecurity#sharepoint#mikrotik#vulnerability
Open analytics
On the site 4 views
min read 3 26.09.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

CISA adds exploited SharePoint and MikroTik flaws to KEV

Open the post on Instagram ↗