
CISA Adds Exploited SharePoint RCE and MikroTik RouterOS Flaws to KEV Catalog
The U.S. cyber agency added CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing attacks in the wild. The RouterOS flaw chains with a login bypass for full router takeover.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two flaws to its Known Exploited Vulnerabilities (KEV) catalog on September 25: CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in MikroTik RouterOS. In both cases the agency cited evidence of active exploitation.
The KEV catalog lists vulnerabilities that attackers are already using in real attacks. Once a flaw is added, U.S. federal agencies are required to apply fixes within a set deadline.
SharePoint Code Injection
CVE-2026-65660 carries a CVSS score of 8.8. It is a code injection flaw in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
Microsoft initially described the issue as a spoofing vulnerability affecting SharePoint Server, then updated its advisory to state that it could be abused to obtain remote code execution.
"As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability," the company said. It has not disclosed who was behind the attacks, when they started, how many organizations were targeted, or what attackers did after getting in.
The MikroTrick Chain
CVE-2026-67279 (CVSS 6.9) is an improper enforcement of behavioral workflow in RouterOS that lets an unauthenticated client open a session channel and send an exec request. Chained with CVE-2026-86060, an argument injection flaw in the RouterOS login process, it forms an exploit codenamed MikroTrick.
According to CERT Polska, the chain grants full administrative control of internet-exposed routers without a password.
"Combining the two vulnerabilities resulted in full unauthenticated access to the administrative console," the Polish agency said.
In a separate analysis, Bishop Fox said it reproduced the complete administrative takeover on vulnerable RouterOS 7.x builds. "MikroTrick combines two failures at different trust boundaries," researcher Emilio Gallegos said.
Deadlines and Fixes
CISA had already added CVE-2026-86060 to the KEV catalog on September 11. Federal Civilian Executive Branch agencies have until September 28 to apply the necessary fixes.
With both flaws now used in real attacks, vendor updates should be installed promptly. Internet-exposed RouterOS routers are especially at risk, because the MikroTrick chain does not require a password.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.