On September 25, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog, adding two vulnerabilities that are confirmed to be under active exploitation. The first is CVE-2026-65660, a critical remote code execution (RCE) vulnerability in Microsoft SharePoint. The second is CVE-2026-67279, a medium-severity flaw in MikroTik RouterOS that can be chained with another vulnerability to achieve full remote administrative control. The inclusion in the KEV catalog mandates that Federal Civilian Executive Branch (FCEB) agencies apply patches or mitigations by September 28, 2026, and serves as a strong advisory for all organizations to prioritize remediation.
CVE-2026-65660CVE-2026-67279CVE-2026-86060. This exploit chain, dubbed "MikroTrick," allows for unauthenticated, full administrative control over vulnerable, internet-exposed routers. This gives an attacker complete control over the network device, allowing them to intercept traffic, modify routing, or use the device as a pivot point.Both vulnerabilities are confirmed by CISA to be actively exploited in the wild. The inclusion in the KEV catalog is based on reliable evidence of ongoing attacks. Threat actors often scan for and exploit vulnerabilities in widely used products like SharePoint and RouterOS shortly after they are disclosed or a proof-of-concept is released. The "MikroTrick" exploit chain highlights the risk of vulnerability chaining, where lower-severity flaws are combined to achieve a critical impact.
The following patterns may help identify vulnerable or compromised systems:
SharePoint ULS Logsw3wp.exe process behavior or suspicious code execution events tied to web requests.MikroTik RouterOS Logs/_layouts/Unusual traffic from MikroTik routerD3-VSD - Vulnerability Scan Detection can help identify scanning activity.D3-SU - Software Update.New details emerge on SharePoint RCE (CVE-2026-65660) exploitation, including webshell deployment, affected versions, and specific hunting/detection methods.
Further analysis of CVE-2026-65660 reveals attackers are deploying webshells after exploiting the SharePoint RCE. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition, allowing low-privileged authenticated users to execute code, with potential for unauthenticated exploitation via chaining. Threat intelligence indicates exploitation began as early as September 24. Detailed hunting hints (w3wp.exe, aspx/ashx files, ULS logs) and detection methods (EDR, FIM, log analysis) are now available to help organizations identify and mitigate compromise.
CISA adds CVE-2026-65660 and CVE-2026-67279 to the KEV catalog.
Deadline for U.S. federal agencies to apply mitigations for the newly added vulnerabilities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.