CISA Flags Actively Exploited Flaws in Microsoft SharePoint and MikroTik Routers
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The first, CVE-2026-65660, affects Microsoft SharePoint Server. Originally described as a spoofing issue, Microsoft has since confirmed it can be exploited to achieve remote code execution, with reliable evidence of attacks observed as of 25 September 2026. Microsoft has not disclosed who is behind the attacks or what actions were taken once systems were compromised.
The second addition is CVE-2026-67279, which security researchers have shown can be chained with a separate flaw, CVE-2026-86060, in an exploit dubbed MikroTrick. According to CERT Polska, combining the two flaws lets an attacker gain full, unauthenticated administrative control of internet-exposed MikroTik RouterOS devices, without needing a password. Bishop Fox independently reproduced the full takeover on vulnerable RouterOS 7.x builds, describing it as a case where a feature meant only for trusted local access became exposed remotely due to a failure in tracking authentication state.
Both vulnerabilities highlight how quickly disclosed flaws can move from theoretical risk to active exploitation. Organisations running affected SharePoint servers or MikroTik routers should treat these as urgent priorities.