The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has highlighted two significant security vulnerabilities within Microsoft SharePoint and MikroTik RouterOS, which are currently being exploited. These issues have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, reflecting their critical nature and active exploitation.
Details of the Vulnerabilities
The first vulnerability, identified as CVE-2026-65660, is a code injection flaw in Microsoft SharePoint with a CVSS score of 8.8. This vulnerability allows an attacker with network access to execute arbitrary code. Originally labeled as a spoofing vulnerability, Microsoft has revised its description to indicate potential remote code execution.
The second vulnerability, CVE-2026-67279, affects MikroTik RouterOS with a CVSS score of 6.9. This issue involves improper enforcement of workflow, enabling unauthenticated users to establish a session and send requests. This vulnerability has been linked with another flaw, CVE-2026-86060, to form an exploit known as MikroTrick.
Impact and Exploitation
Microsoft has confirmed observing active attacks leveraging CVE-2026-65660 as of late September 2026, although details on the attackers or the extent of the impact remain undisclosed. Meanwhile, the MikroTrick exploit combines CVE-2026-67279 with CVE-2026-86060, allowing attackers to gain administrative control over vulnerable routers without authentication, as reported by CERT Polska.
Security firm Bishop Fox successfully reproduced the exploit on RouterOS 7.x versions, demonstrating the significant risk posed by these combined vulnerabilities. Emilio Gallegos from Bishop Fox highlighted that this exploit reveals a critical design flaw where trust boundaries are improperly managed, turning a local feature into a remote vulnerability.
Response and Mitigation
In response to these vulnerabilities, CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies implement necessary patches by the end of September 2026. This directive underscores the urgency and severity of addressing these security flaws to prevent further exploitation.
The ongoing exploitation of these vulnerabilities underscores the importance of timely patching and robust security measures. Organizations using Microsoft SharePoint and MikroTik RouterOS are advised to assess their systems and apply the recommended patches to mitigate potential risks.
As cyber threats continue to evolve, maintaining up-to-date security protocols and monitoring for vulnerabilities is crucial in safeguarding against exploitation.
