CISA Catalogs Exploited SharePoint and MikroTik Flaws

CISA Adds SharePoint, MikroTik Bugs to Known Exploited List

HIGH
September 26, 2026
September 27, 2026
4m read
VulnerabilityPatch ManagementRegulatory

Related Entities(initial)

Organizations

CERT PolskaCISAMicrosoftMikroTik

Products & Tech

RouterOSSharePoint

Other

Known Exploited Vulnerabilities (KEV) Catalog

CVE Identifiers

CVE-2026-65660
HIGH
CVSS:8.8
CVE-2026-67279
MEDIUM
CVSS:6.9
CVE-2026-86060
NONE

Full Report(when first published)

Executive Summary

On September 25, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog, adding two vulnerabilities that are confirmed to be under active exploitation. The first is CVE-2026-65660, a critical remote code execution (RCE) vulnerability in Microsoft SharePoint. The second is CVE-2026-67279, a medium-severity flaw in MikroTik RouterOS that can be chained with another vulnerability to achieve full remote administrative control. The inclusion in the KEV catalog mandates that Federal Civilian Executive Branch (FCEB) agencies apply patches or mitigations by September 28, 2026, and serves as a strong advisory for all organizations to prioritize remediation.


Vulnerability Details

Microsoft SharePoint Code Injection Vulnerability (CVE-2026-65660)

  • CVE ID: CVE-2026-65660
  • Affected Product: Microsoft SharePoint
  • CVSS Score: 8.8 (High)
  • Vulnerability Type: Remote Code Execution (RCE)
  • Description: This vulnerability allows an authenticated attacker to execute arbitrary code over the network. Although initially classified by Microsoft as a spoofing flaw, its severity was later upgraded to RCE. On September 25, Microsoft confirmed it had evidence of active exploitation, though details about the attackers or the scope of the attacks were not provided. This type of vulnerability is highly dangerous as SharePoint servers often store sensitive internal documents and are frequently internet-facing.

MikroTik RouterOS Improper Workflow Enforcement (CVE-2026-67279)

  • CVE ID: CVE-2026-67279
  • Affected Product: MikroTik RouterOS
  • CVSS Score: 6.9 (Medium)
  • Vulnerability Type: Improper Enforcement of Behavioral Workflow
  • Description: This flaw allows an unauthenticated client to open a session channel and send an execution request. While only medium severity on its own, security researchers at CERT Polska have demonstrated that it can be chained with another vulnerability, CVE-2026-86060. This exploit chain, dubbed "MikroTrick," allows for unauthenticated, full administrative control over vulnerable, internet-exposed routers. This gives an attacker complete control over the network device, allowing them to intercept traffic, modify routing, or use the device as a pivot point.

Exploitation Status

Both vulnerabilities are confirmed by CISA to be actively exploited in the wild. The inclusion in the KEV catalog is based on reliable evidence of ongoing attacks. Threat actors often scan for and exploit vulnerabilities in widely used products like SharePoint and RouterOS shortly after they are disclosed or a proof-of-concept is released. The "MikroTrick" exploit chain highlights the risk of vulnerability chaining, where lower-severity flaws are combined to achieve a critical impact.

Impact Assessment

  • SharePoint (CVE-2026-65660): A compromise of a SharePoint server can lead to a massive internal data breach. Attackers can gain access to all documents stored on the platform, which could include intellectual property, financial records, and employee PII. The server can also be used as a foothold to move laterally within the corporate network.
  • MikroTik (CVE-2026-67279): A compromised router gives an attacker control over a network's traffic. This can be used for espionage (man-in-the-middle attacks), disrupting services (denial-of-service), or launching further attacks from a trusted position within the network. Given MikroTik's popularity in small-to-medium businesses and emerging markets, a large number of devices are likely vulnerable.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable or compromised systems:

Type
log_source
Value
SharePoint ULS Logs
Description
Monitor for unexpected w3wp.exe process behavior or suspicious code execution events tied to web requests.
Type
log_source
Value
MikroTik RouterOS Logs
Description
Look for unexpected session channel creation from unknown IP addresses or unauthorized administrative actions.
Type
url_pattern
Value
/_layouts/
Description
Scrutinize web logs for unusual requests to SharePoint's LAYOUTS directory, which is often a target for exploits.
Type
network_traffic_pattern
Value
Unusual traffic from MikroTik router
Description
Monitor for routers initiating connections to known malicious IPs or acting as proxies.

Detection Methods

  • Vulnerability Scanning: Use a vulnerability scanner to actively identify SharePoint servers and MikroTik routers on your network that are vulnerable to these CVEs. D3FEND's D3-VSD - Vulnerability Scan Detection can help identify scanning activity.
  • Log Analysis: For SharePoint, analyze IIS and SharePoint ULS logs for signs of exploitation attempts. For MikroTik, enable and forward system logs to a central SIEM to monitor for unauthorized login attempts or configuration changes.

Remediation Steps

  1. Prioritize and Patch: The primary remediation is to apply the security updates provided by Microsoft and MikroTik for these vulnerabilities. Due to their KEV status, these should be treated as critical patches. This is a core tenet of D3FEND's D3-SU - Software Update.
  2. Follow BOD 26-04: Federal agencies must remediate these flaws by the September 28, 2026 deadline. All other organizations are strongly encouraged to do the same.
  3. Reduce Attack Surface: If patching is not immediately possible, restrict access to SharePoint servers and MikroTik management interfaces. Do not expose administrative interfaces to the public internet. Use a VPN with multi-factor authentication for remote management.

Timeline of Events

1
September 25, 2026
CISA adds CVE-2026-65660 and CVE-2026-67279 to the KEV catalog.
2
September 26, 2026
This article was published
3
September 28, 2026
Deadline for U.S. federal agencies to apply mitigations for the newly added vulnerabilities.

Article Updates

September 27, 2026

Severity increased

New details emerge on SharePoint RCE (CVE-2026-65660) exploitation, including webshell deployment, affected versions, and specific hunting/detection methods.

Further analysis of CVE-2026-65660 reveals attackers are deploying webshells after exploiting the SharePoint RCE. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition, allowing low-privileged authenticated users to execute code, with potential for unauthenticated exploitation via chaining. Threat intelligence indicates exploitation began as early as September 24. Detailed hunting hints (w3wp.exe, aspx/ashx files, ULS logs) and detection methods (EDR, FIM, log analysis) are now available to help organizations identify and mitigate compromise.

Timeline of Events

1
September 25, 2026

CISA adds CVE-2026-65660 and CVE-2026-67279 to the KEV catalog.

2
September 28, 2026

Deadline for U.S. federal agencies to apply mitigations for the newly added vulnerabilities.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Active ExploitationCISAKEVMikroTikSharePoint

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.