SharePoint RCE and MikroTik Flaws Actively Exploited

SharePoint RCE and MikroTik Flaws Actively Exploited

Estimated reading time: 5 minutes · Last updated:

CISA on 25 September 2026 added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-65660, a SharePoint issue now described as allowing remote code execution, and CVE-2026-67279 in MikroTik RouterOS that has been chained to enable administrative takeover. The SharePoint entry carries a CVSS score of 8.8 and Microsoft says it has "reliable evidence of observed attacks" against the flaw. CERT Polska and Bishop Fox have published technical analyses showing that chaining RouterOS flaws can yield full unauthenticated control of internet-exposed devices. CISA's listing has an operational effect: Federal Civilian Executive Branch agencies face a remediation deadline tied to related RouterOS fixes.

Combining the two vulnerabilities resulted in full unauthenticated access to the administrative console,

CERT Polska

Key takeaways

  • CISA action: CISA added CVE-2026-65660 and CVE-2026-67279 to its Known Exploited Vulnerabilities catalog on 25 September 2026.
  • SharePoint severity: CVE-2026-65660 is now described as allowing remote code execution and carries a CVSS score of 8.8, per Microsoft.
  • MikroTik chain: CERT Polska says chaining CVE-2026-67279 with CVE-2026-86060 results in full unauthenticated administrative access to RouterOS.
  • FCEB deadline: Federal Civilian Executive Branch agencies have until 28 September 2026 to apply the necessary fixes tied to the RouterOS KEV listing.

Why CISA added these CVEs to the KEV catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog on 25 September 2026 after seeing evidence that attackers were exploiting them in the wild. The KEV catalog is used to highlight flaws with observed exploitation so that organisations prioritise mitigation; inclusion often prompts mandatory or accelerated remediation in federal contexts.

In this instance the two entries cover very different failure modes: one targets Microsoft SharePoint and now carries a high-severity rating, while the other targets MikroTik RouterOS and forms part of a multi-bug chain that allows unauthenticated takeover. The catalog listing therefore signals both immediate operational risk and a need for defenders to consult vendor advisories and network inventories to identify exposed instances.

What Microsoft disclosed about the SharePoint issue

CVE-2026-65660 was first characterised as a spoofing vulnerability in earlier vendor notes, but Microsoft updated its guidance to say the flaw can be abused to obtain remote code execution. The company stated that "As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," and it assigned the defect a CVSS score of 8.8.

Microsoft has not published details that would identify who is responsible for the attacks, when exploitation began, how many organisations were targeted, whether intrusions succeeded, or what actions attackers took post-compromise. Those unknowns leave defenders with a high-severity technical indicator (RCE capability) but without a public tally of impact or actor attribution.

How the MikroTik RouterOS chain achieves takeover

CERT Polska's analysis shows that CVE-2026-67279 and CVE-2026-86060 can be combined into an exploit chain that gives full administrative access to vulnerable routers without a password. CERT Polska wrote that "Combining the two vulnerabilities resulted in full unauthenticated access to the administrative console." The first flaw lets an unauthenticated client open a session channel; the second lets that connection be treated as a trusted administrative identity in the login process.

Bishop Fox reproduced the takeover on RouterOS 7.x builds and highlighted the design issue: functionality meant for trusted local callers becomes reachable remotely when an upstream component fails to maintain authentication state. Security researcher Emilio Gallegos described MikroTrick as combining failures at different trust boundaries that together expose privileged interfaces to remote callers.

Immediate operational impacts and responses

One concrete operational effect is a Federal Civilian Executive Branch deadline: CISA added CVE-2026-86060 to the KEV catalog on 11 September 2026 and federal agencies have until 28 September 2026 to apply the necessary fixes associated with the RouterOS entries. That timeline compresses remediation windows for administrators of internet-facing routers.

Beyond the FCEB deadline, the public disclosures from Microsoft, CERT Polska and Bishop Fox give network teams CVE identifiers and technical write-ups they can use to prioritise inventories and exposure scanning. Microsoft updated its advisory for the SharePoint defect; CERT Polska and Bishop Fox published technical analyses for the MikroTik chain that operators can consult when assessing RouterOS instances.

Key differences between the SharePoint and MikroTik issues
Component CVE CVSS Impact Source
Microsoft SharePoint CVE-2026-65660 8.8 Authenticated attacker can obtain remote code execution Microsoft
MikroTik RouterOS CVE-2026-67279 (chained with CVE-2026-86060) 6.9 Chained exploit yields full unauthenticated administrative access CERT Polska; Bishop Fox

Cases for and against rapid community containment

The case for

  • KEV inclusion places the flaws on an operational remediation track and imposes a federal deadline that can force fast patching or configuration changes.
  • Multiple public technical analyses (CERT Polska and Bishop Fox) provide actionable indicators and reproduction steps that defenders can use to identify and harden affected systems.

The case against

  • Microsoft has not disclosed attacker attribution, the start date of exploitation, or the number of successful compromises, leaving defenders uncertain about exposure and attacker intent.
  • The MikroTik chain demonstrates a design-class failure that may be reproducible across builds; Bishop Fox reproduced the takeover on RouterOS 7.x, which raises the risk for operators who run those versions.

What to be careful about

  • Internet-exposed RouterOS instances can be taken fully over without authentication when the two CVEs are chained, per CERT Polska and Bishop Fox.
  • CVE-2026-65660 enables remote code execution in SharePoint when abused by an authorized attacker, creating high-severity lateral-movement and data-access risk.
  • Key impact metrics are missing: Microsoft has not disclosed how many organisations were targeted or what attackers did after exploitation, which complicates incident triage.

The bottom line

The CISA KEV additions make two concurrent but distinct risks explicit: a high-severity SharePoint defect that Microsoft now links to remote code execution, and a RouterOS chain that permits unauthenticated administrative takeover when two CVEs are combined. Named technical analyses from CERT Polska and Bishop Fox give defenders concrete reproduction details and indicators, while Microsoft’s advisory confirms observed exploitation as of 25 September 2026. Crucial gaps remain — the scale of compromises and attacker identities are not public — so organisations should use the published CVE identifiers and vendor guidance as the basis for inventory checks and patch planning.

What to watch

  • Federal Civilian Executive Branch remediation deadline on 28 September 2026 for the RouterOS KEV listing.
  • Watch for vendor patch advisories from Microsoft and MikroTik; no date has been set in the public disclosures.
  • Watch for follow-up technical reports or indicators from CERT Polska and Bishop Fox; no date has been set.

Frequently asked questions

What exactly did Microsoft say about CVE-2026-65660?

Microsoft updated its advisory to say CVE-2026-65660 can be abused to obtain remote code execution and reported that "As of 9/25/2026, Microsoft had reliable evidence of observed attacks"; the flaw carries a CVSS score of 8.8.

How does the MikroTik exploit chain work?

CERT Polska found that CVE-2026-67279 lets an unauthenticated client open a session channel while CVE-2026-86060 can cause the login process to accept an attacker-controlled identity, and combining them yields full administrative access according to CERT Polska and Bishop Fox.

What operational deadline does the KEV listing impose?

CISA added CVE-2026-86060 to its KEV catalog on 11 September 2026 and Federal Civilian Executive Branch agencies have until 28 September 2026 to apply the necessary fixes associated with the RouterOS listing.



Share:

Categories

Newest course every month

Advertise your offline course to a wider audience with our landing page.

You May Also Like

CISA added CVE-2026-65660 (SharePoint RCE) and MikroTik CVE-2026-67279 to its Known Exploited Vulnerabilities catalog after evidence of active
A UC San Diego and Inria Nancy paper shows a novel textbook RSA attack that cuts required operations (e.g. 280→265...
Wyoming courts data breach: West Publishing hack may have exposed case records from 2015–2025; the Wyoming Judicial Branch is awaiting...