On 25 September 2026, CISA added two vulnerabilities to the Known Exploited Vulnerabilities catalog — CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in MikroTik RouterOS. Both are marked as actively exploited. Together with the previously added CVE-2026-86060, they form three related threats affecting corporate collaboration systems and network infrastructure. Organizations using SharePoint Server or MikroTik routers accessible from the internet must apply patches by the CISA deadline of 28 September 2026.
SharePoint vulnerability: from spoofing to remote code execution
CVE-2026-65660 is a code injection vulnerability in Microsoft Office SharePoint with a stated CVSS score of 8.8. It allows an authenticated attacker to execute arbitrary code over the network. Notably, Microsoft initially classified this issue as a spoofing vulnerability but later revised the description, acknowledging the possibility of remote code execution. According to reports, as of 25 September 2026 Microsoft had “reliable evidence of observed attacks” exploiting this vulnerability.
At the same time, Microsoft has not disclosed who is exploiting it, when the attacks began, how many organizations have been targeted, or what actions the attackers took after compromise. The range of affected SharePoint Server versions is also not specified in the available materials. Earlier, we provided a detailed analysis of the reclassification history of this vulnerability in the article “CVE-2026-65660: the debate over classifying the SharePoint vulnerability”.
Important caveat: during data verification, a discrepancy was identified — in the NVD database, the entry with a description matching the characteristics (a SharePoint vulnerability allowing an authenticated attacker to execute code over the network) is registered under the identifier CVE-2026-65665. Administrators are advised to refer to the official Microsoft advisory for accurate information on affected versions and available patches.
MikroTrick: the RouterOS exploitation chain
The second part of the KEV update concerns MikroTik RouterOS and arguably presents a more acute operational threat. CVE-2026-67279 (stated CVSS score 6.9) is a vulnerability in the improper enforcement of behavioral restrictions, allowing an unauthenticated client to open a session channel and send a command execution request. On its own it is of moderate severity, but when combined with CVE-2026-86060 — an argument injection vulnerability in the RouterOS authentication process — it forms an exploitation chain codenamed MikroTrick.
According to CERT Polska, the combination of these two vulnerabilities provides full unauthenticated access to the router’s administrative console. The mechanism works as follows: CVE-2026-67279 allows an unauthenticated client to create a session channel, and CVE-2026-86060 allows the attacker to inject a controlled policy mask into the authentication process. According to reports, Bishop Fox reproduced full administrative takeover on vulnerable RouterOS 7.x builds.
Researcher Emilio Gallegos from Bishop Fox described the essence of the issue as follows: functionality intended exclusively for trusted local calls turns into a remote attack surface when the higher-level component loses control over the authentication state. This is a classic example of broken trust boundaries in privileged software.
CVE-2026-86060 was added to the KEV catalog earlier — according to the catalog, on 10 September 2026, with a remediation deadline of 13 September. We published a detailed technical breakdown of the MikroTrick chain in the article “MikroTrick: exploiting MikroTik RouterOS vulnerabilities over SSH”.
Impact assessment
The two threats affect fundamentally different segments of infrastructure, but both pose a serious risk:
- SharePoint Server is widely used in corporate environments for document management and collaboration. Exploiting CVE-2026-65660 requires authentication, which narrows the pool of attackers but does not reduce the severity: compromised credentials or insider access make the attack realistic. Remote code execution on a SharePoint server can lead to access to confidential documents, lateral movement across the network, and compromise of Active Directory.
- MikroTik RouterOS — MikroTik routers are widely used in small and medium-sized businesses, by internet service providers, and in home networks. The MikroTrick chain does not require authentication and targets devices accessible from the internet. Taking over a router opens up opportunities for traffic interception, DNS redirection, building botnets, and using the device as an entry point into the internal network.
Recommendations
- SharePoint Server: install the security updates specified in the Microsoft advisory. Check logs for signs of anomalous activity by authenticated users — execution of atypical operations, access to uncharacteristic resources.
- MikroTik RouterOS: update the firmware to a version that fixes CVE-2026-67279 and CVE-2026-86060. If immediate updating is not possible, restrict access to the router’s administrative interface from the internet using allowed IP address lists or a VPN.
- Deadlines: for U.S. federal civilian executive branch agencies (FCEB), the remediation deadline for CVE-2026-65660 and CVE-2026-67279 is 28 September 2026. Commercial organizations are advised to follow similar timelines.
- Inventory MikroTik routers running RouterOS 7.x that are accessible from the internet. Prioritize devices with open management ports.
The MikroTrick chain is the most acute threat among the three vulnerabilities discussed: it does not require authentication, targets perimeter devices, and has already been confirmed through independent reproduction. Organizations with MikroTik routers accessible from the internet should treat firmware upgrades or restricting management access as a matter of hours, not days.